Impact
n8n versions prior to 1.123.73, 2.35.4, and 2.36.2 contain a flaw in the Strapi, SeaTable, and Mailcheck nodes that send decrypted credentials to the authentication endpoint using a raw legacy HTTP helper without error handling. The plaintext secret is persisted in execution error data, and any authenticated user can retrieve it via the REST API, bypassing the blank-value redaction enforced by the credentials API.
Affected Systems
The vulnerability affects n8n version 1.123.72 and earlier, 2.35.4, and 2.36.2. The affected components are the Strapi, SeaTable, and Mailcheck nodes within those releases.
Risk and Exploitability
The CVSS score is 7.1, the EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector involves an authenticated user accessing their own execution logs through the REST API. Exploitation requires that the user has legitimate credentials to n8n and that the application’s error data is accessible via the API.
OpenCVE Enrichment