Impact
An authority‑blindness flaw in the AI Agents feature of n8n allows a member‑level user with use‑only access to a shared credential to point an MCP connector at any arbitrary URL. Because the Allowed HTTP Request Domains restriction is not enforced, the credential’s secret can be sent to an attacker‑controlled external server. The compromised data is the credential secret, exposing an improper control of security‑relevant information.
Affected Systems
Vulnerable versions of the n8n open‑source workflow automation platform are those prior to 2.27.4 and 2.28.1. Deployments that enable the AI shared credentials with use‑only rights granted to member‑level users fall under the affected user model.
Risk and Exploitability
The CVSS score of 7.1 reflects high impact with a modest exploitation effort. An EPSS score of < 1% denotes a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not present in the CISA KEV catalog. Attackers would likely exploit the a malicious endpoint, thereby exfiltrating the credential secret without needing elevated privileges.
OpenCVE Enrichment
Github GHSA