Authorization bypass through user-controlled key in n8n - #VU150764
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the credential test endpoint when resolving project-scoped workflow variables using a project ID supplied in the request body. A remote user can submit a credential test request specifying an arbitrary project and a controlled destination to disclose sensitive information.