Impact
The OpenAI Chat Model node in the n8n workflow automation platform prevented user-facing calls from violating the credential allowed-domain restriction, but left the model-search dropdown endpoint unguarded. When a workflow editor sets the options.baseURL parameter to an arbitrary host, a request to the searchModels path is issued with the user’s stored OpenAI credential. The missing assertion that verifies the credential’s allowed domains caused the credential to be sent to the attacker‑controlled host. This creates a potential for exposing sensitive API keys to an unintended destination, effectively bypassing the intended domain restriction and allowing an attacker to gain unauthorized access to external services tied to those credentials.
Affected Systems
The vulnerability affects the open‑source n8n workflow automation platform, specifically any installation using version 1.123.75 or earlier, or version 2.37.6 or earlier, or version 2.38.1 or earlier. The issue is fixed starting with n8n releases 1.123.76, 2.37.7, and 2.38.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact and the common weakness classification suggests that the flaw allows a user with access to the workflow editor to influence outbound credentials. Exploitation requires the attacker to be able to modify workflow configurations or inject custom options.baseURL values, which may be feasible in environments where n8n is exposed to internal users or less‑privileged administrative accounts. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalogue, so while the risk is real, the probability of exploitation at the time of analysis is unclear.
OpenCVE Enrichment
Github GHSA