Impact
A flaw in the HTTP Request node allows an authenticated member with edit rights to a shared workflow to reference another user's credential. Because the system compares the unresolved expression instead of the resolved credential type, the ownership check is bypassed. The targeted credential is then loaded at execution time, enabling the attacker to use or exfiltrate a credential they were not originally granted. The weakness corresponds to CWE-639, unauthorized use of privileged credentials.
Affected Systems
The issue affects n8n versions prior to 1.123.67, 2.31.5, and 2.32.1. Any deployment hosting these releases is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity exploit. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Inferred attack requires an authenticated member who can edit a shared workflow and knowledge of the target credential’s identifier, implying an authenticated, internal attacker. Successful exploitation permits unauthorized access to credentials and potential exfiltration of sensitive data.
OpenCVE Enrichment