Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9vf-c827-9m93

Опубликовано: 01 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.8
CVSS3: 8.5

Описание

n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.

n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.

EPSS

Процентиль: 13%
0.00236
Низкий

5.8 Medium

CVSS4

8.5 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.5
nvd
2 дня назад

n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.

EPSS

Процентиль: 13%
0.00236
Низкий

5.8 Medium

CVSS4

8.5 High

CVSS3

Дефекты

CWE-639