Impact
The vulnerability exists in n8n’s Instance AI credential setup flow, which accepts a credential test or verification URL without validating that it matches the workflow node’s origin. When a user injects attacker‑controlled fetched content into the setup process, the resulting URL can point to any external site. This causes authenticated requests, redirects or probes to reach that arbitrary origin, potentially exposing credentials or allowing the attacker to gather sensitive data or execute unauthorized actions on behalf of the user.
Affected Systems
The flaw affects the open source workflow automation platform n8n from n8n-io. Versions prior to 2.37.7 and 2.38.2 are vulnerable. Users running these releases are at risk until they upgrade to a patched version.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. An attacker must first gain a legitimate authenticated session and inject malicious content into the credential setup process. Once injected, the attacker can manipulate the service to send requests to any chosen third‑party origin, potentially exfiltrating data or performing unauthorized actions. The risk is moderate, driven by the need for user interaction and limited to authenticated accounts.
OpenCVE Enrichment
Github GHSA