Impact
A flaw in n8n versions before 2.36.2 allows crafted inline sub‑workflows to reference credentials that the workflow editor does not own. When such a workflow is executed under an identity that possesses the referenced credential, the sub‑workflow resolves the secret and can deliver it to an attacker‑controlled endpoint, leading to credential exfiltration. This flaw violates authorization controls and is classified under CWE‑863, exposing credentials to unauthorized parties.
Affected Systems
The vulnerability affects n8n‑io’s n8n product in all releases before 2.35.4 and before 2.36.2, including the 2.35.x series and the 2.36.0‑2.36.1 releases. Users running these versions who can edit or update shared workflows via the editor, API, or MCP are at risk.
Risk and Exploitability
The CVSS score of 7.2 signals moderate‑to‑high severity. EPSS data is unavailable, so the exact exploitation probability is unknown. The vulnerability is not listed in CISA KEV. The likely attack vector involves a user who can create or modify a shared workflow to reference a credential they do not own, then causing the workflow to run under an account that has that credential, enabling the sub‑workflow to resolve the secret and exfiltrate it to an attacker‑controlled endpoint.
OpenCVE Enrichment