Impact
This vulnerability arises from a missing per‑project authorization check in the Insights API endpoints. An attacker who is authenticated and has the insights scope can provide arbitrary projectId parameters to the API and read workflow names and execution statistics from any project, even if the user has no membership in that project. The exposed data constitutes a moderate‑severity information disclosure, potentially revealing operational details and usage patterns across the organization.
Affected Systems
The issue affects the n8n workflow automation engine before version 2.36.2. All users running these earlier releases are potentially vulnerable until they upgrade to 2.36.2 or later.
Risk and Exploitability
The CVSS score of 5.3 reflects a medium risk. The EPSS score is not available, so the expected exploitation probability cannot be quantified. This vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with insight permissions; the attacker can supply any projectId to the API and obtain sensitive information. The attack can be performed over the network once the user has authenticated.
OpenCVE Enrichment