Impact
n8n versions prior to 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when the authentication type is set to an expression. The flaw allows an attacker who has a valid MCP Bearer API key and knows a target credential ID to persist unauthorized cross‑project credential references on workflows that belong to other projects. This results in the attacker gaining access to credentials that were not intended for those projects, violating confidentiality and potentially enabling further exploitation.
Affected Systems
n8n-io:n8n, all versions before 2.34.1
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker requires possession of a valid MCP Bearer API key, which is typically limited to trusted users, but once obtained the bypass can be exploited within the same system to reference credentials across projects.
OpenCVE Enrichment