Impact
An attacker with a role that includes role:manageProject can request member information for any project by using the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints. Because the controller omitted the project:list permission check, the API returns the names and email addresses of members belonging to a project the caller could not list. The vulnerability is a classic example of missing authorization (CWE‑862) and results in the confidential personal information of users being disclosed to an unauthorized user. The impact is the exposure of PII across tenant boundaries, compromising confidentiality but not providing control or data modification capabilities.
Affected Systems
The problem exists in the n8n workflow automation platform. Versions prior to 2.37.7 and prior to 2.38.2 contain the vulnerability, as the role controller in packages/cli/src/controllers/role.controller.ts omitted the necessary project scope check. The fix was included in releases 2.37.7 and 2.38.2, so any installation running those or newer releases is no longer vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a low‑to‑medium severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. An authenticated user with the manageProject privilege can exploit the flaw by calling the exposed API endpoints and providing arbitrary project identifiers. Because the attacker only needs existing role:manageProject permissions, lateral movement within a tenant is not required; the weakness is purely an authorization oversight. The risk is primarily the unauthorized PII disclosure and should be addressed promptly by applying the patch.
OpenCVE Enrichment
Github GHSA