CyberRota Analysis
AI-GeneratedVersions of n8n prior to 1.123.80 are vulnerable to a credential tampering issue that allows attackers with editor access to shared workflows to exploit duplicate node IDs, bypassing the workflow credential tamper guard. This can lead to the unauthorized retention of victim credentials and redirection of sensitive information to attacker-controlled hosts. Organizations using n8n should prioritize patching to mitigate the risk of credential theft and potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.