Impact
In versions of the workflow automation platform before 1.123.76, 2.37.7, and 2.38.2 the source control push endpoint accepted a list of files supplied by the client and deleted those files without reconciling them against the server‑side state for the authenticated user. An attacker who is an authenticated project‑scoped user—such as a project administrator—can thus reference files belonging to other projects and delete their workflows and credentials. The result is loss of critical automation logic and stored secrets, effectively a form of data sabotage that only requires legitimate credentials within the platform.
Affected Systems
The affected product is n8n from n8n‑io, with vulnerable versions older than 1.123.76 for the 1.x series and older than 2.37.7 or 2.38.2 for the 2.x series. The vulnerability exists only for installations that have the Source Control (Environments) enterprise feature licensed, enabled, and connected to a remote repository.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate impact, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the enterprise Source Control feature to be activated and a legitimate project‑scoped user to submit a crafted push request, after which the attacker can delete workflows and credentials from projects to which they normally have no access.
OpenCVE Enrichment