Impact
The flaw occurs in the HTTP Request node’s pagination expression in the open‑source workflow automation platform. An authenticated member with use‑only editor permissions to a shared workflow can trigger the $request object, leading credential‑populated headers to be exposed and the secret values to be exfiltrated through the resulting item data. This is a high Information Disclosure vulnerability that could compromise the confidentiality of stored credentials that were intended to remain private, involving CWE‑200 and CWE‑522.
Affected Systems
Known affected versions are n8n releases prior to 1.123.61, 2.27.4, and 2.28.1. Any deployment of these versions that hosts shared workflows containing HTTP Request nodes with pagination expressions is vulnerable. The product n8n, developed by n8n-io, is the software at risk.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, while the EPSS score of less than 1 % (approximately 0.00294) shows a very low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited known exploit activity. The attacker must be an authenticated contributor with editor access to a shared workflow that contains an HTTP Request node with a pagination expression. Although publicly documented exploits are absent, the potential for confidential credential disclosure warrants timely mitigation.
OpenCVE Enrichment
Github GHSA