Impact
The vulnerability permits path injection by directly interpolating workflow‑controlled index and document identifiers into REST request paths without proper encoding. An attacker can supply an identifier that contains path separators or dot segments, causing the request to target a different index or a cluster administration endpoint under the stored Elasticsearch credentials. This can lead to unauthorized data discovery, modification or deletion, and potentially elevate privileges within an Elasticsearch cluster.
Affected Systems
The issue affects n8n-io:n8n workflows running any of the following versions: any release before 1.123.76, 2.37.7, or 2.38.2.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires input of a malicious identifier in a workflow; therefore the attack vector is likely an insider or an attacker who has gained the ability to create or modify workflows. No publicly available exploit is known, but the risk remains if untrusted users can define identifiers that are passed to Elasticsearch nodes.
OpenCVE Enrichment
Github GHSA