Descrição
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node-s top-level credentials and not for credentials referenced inside an Execute Sub-workflow node-s inline workflow JSON. A member with Editor access to a shared workflow (when workflow sharing is enabled) who knows a target credential-s ID can reference that credential in the inline JSON; it passes save-time and runtime validation and resolves in the parent workflow-s project context, allowing the attacker to use or exfiltrate credentials they are not permitted to access.
CVSS 7.2EPSS 0%Risco 0.72
Ver fonte- Publicação
- 2026-08-11 13:19:06
- Última alteração
- 2026-08-11 18:18:24
- Vetor
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X