Impact
This vulnerability arises from a missing userId filter in the /rest/active-workflows endpoint and related event notifier services. As a result, any authenticated member can retrieve the list of all active workflow IDs on the instance, and can also receive lifecycle events—including activation, deactivation, publication and errors—for workflows they are not authorized to access. The disclosed data includes workflow IDs, version IDs and activation error details, which can help an attacker enumerate existing workflows, discover workflow versions, and potentially predict scheduling or use patterns. The weakness is an access control flaw, identified as CWE-862.
Affected Systems
The open source n8n workflow automation platform from n8n-io is impacted. Versions earlier than 1.123.76, 2.37.7, and 2.38.2 are vulnerable. The issue is fixed in the corresponding releases of those versions.
Risk and Exploitability
The CVSS score for this issue is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated member status to trigger the affected endpoints; thus exploitation is feasible for any user with valid credentials, though it does not allow arbitrary code execution or privilege escalation. The risk is therefore moderate, mainly associated with unintended information leakage of workflow identifiers and error details.
OpenCVE Enrichment
Github GHSA