Impact
The vulnerability allows information disclosure by returning the underlying HTTP client error during a GraphQL request failure. The error contains request headers that include a decrypted credential secret. The execution engine persists this error message unchanged, so any authenticated user who can read the run data can recover the credential secret.
Affected Systems
n8n-io’s n8n before 1.123.69, before 2.33.4, and before 2.34.1 are affected. The GraphQL node in these releases is the source of the issue.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity impact when exploited. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploit yet. Attackers must be authenticated to DB and able to trigger a GraphQL request that fails at the connection level; the resulting stored error then exposes the credential secret.
OpenCVE Enrichment