Impact
The vulnerability in n8n allows an allowed‑domains bypass within the GraphQL node. When the node’s Authentication parameter is set to expression mode, every authentication‑gated credential selector is regarded as active. If two different credential types are attached, the node applies the allowed‑domains policy of only the first credential while still attaching material from both. An authenticated user with workflow‑authoring rights can thus send a domain‑restricted credential to an attacker‑controlled endpoint, exfiltrating it with the permissions of the leaked credential.
Affected Systems
This issue affects n8n releases prior to 1.123.69 and prior to 2.33.4 for major version 2.x, as well as prior to 2.34.1 for minor version 2.x. The affected product is n8n from n8n‑io.
Risk and Exploitability
The CVSS score of 5.1 classifies the impact as moderate. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated user who possesses workflow‑authoring privileges. Based on the description, it is inferred that an attacker must first author a workflow; once the bypass is triggered, a credential can be exfiltrated to an external endpoint. Because the exploit demands specific user rights and no public exploits at the time of analysis, the overall risk is moderate, but an organization allowing extensive workflow‑authoring should consider it a high priority for patching.
OpenCVE Enrichment