Impact
The vulnerability in n8n allows a log streaming event destination to decrypt any generic HTTP credential it references without checking ownership. As a result, a user with a custom global role that includes Log Streaming scopes can point the destination at credentials from other projects and have the plaintext secret sent to an attacker‑controlled endpoint, leading to confidential credential leakage and potential compromise of downstream services.
Affected Systems
n8n – the open source workflow automation platform from n8n-io. Versions prior to 1.123.76, 2.37.7, and 2.38.2 are impacted. Any installation running those releases with a global role that grants Log Streaming permissions is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, so the likelihood of widespread exploitation is unclear. However, the description implies that an attacker can exploit the flaw once a custom global role with Log Streaming scopes exists, enabling straightforward credential theft. The attack vector is inferred to be through the Log Streaming destination mechanism within the application code, requiring that the attacker can create or manipulate such a role.
OpenCVE Enrichment
Github GHSA