Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN896
_____________________________________________________________________

DATE                : 16/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running n8n versions prior to 2.40.1, 
                                          2.39.6.
  
=====================================================================
https://github.com/n8n-io/n8n/security/advisories/GHSA-rx55-8qhx-4hwx
https://github.com/n8n-io/n8n/security/advisories/GHSA-89p4-6h98-c7xm
https://github.com/n8n-io/n8n/security/advisories/GHSA-gx6g-2hm7-c4xf
https://github.com/n8n-io/n8n/security/advisories/GHSA-rqch-9jrh-cr8w
https://github.com/n8n-io/n8n/security/advisories/GHSA-597w-c3jh-g8fg
https://github.com/n8n-io/n8n/security/advisories/GHSA-4wf3-rgqr-xcp3
https://github.com/n8n-io/n8n/security/advisories/GHSA-7gvh-q9w3-wqqx
https://github.com/n8n-io/n8n/security/advisories/GHSA-fmmv-p585-7c8x
https://github.com/n8n-io/n8n/security/advisories/GHSA-w24g-6454-7w7f
https://github.com/n8n-io/n8n/security/advisories/GHSA-xrqg-3xcp-h45x
https://github.com/n8n-io/n8n/security/advisories/GHSA-7gjv-rcf8-x5qc
https://github.com/n8n-io/n8n/security/advisories/GHSA-9rhv-fhr8-7q5r
_____________________________________________________________________

Dynamic Credentials Authorize Endpoint Leaks Session Token to
Attacker-Controlled Resolver

High
Matsuuu published GHSA-rx55-8qhx-4hwx

Package
n8n (npm)

Affected versions
< 2.40.1
< 2.39.6

Patched versions
>= 2.40.1
>= 2.39.6


Description

Impact

The Dynamic Credentials authorize and revoke endpoints forwarded the
caller's raw session token to the configured resolver, missing the
check the execution path already applied. Since a workflow's fallback
resolver is settable with plain workflow:update, a user who can
register a resolver could capture any collaborator's — or the
owner's — session during the ordinary "Connect your account" step,
and with it read credentials they have no access to.
Patches

The issue has been fixed in n8n versions 2.39.6 and 2.40.1. Users
should upgrade to one of these versions or later to remediate the
vulnerability.

Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Disable the Dynamic Credentials module if it is not required.
    Audit and revoke any custom global roles that carry the
credentialResolver:create scope, limiting that scope to fully
trusted administrators only.
    Review registered credential resolvers and remove any that
are not recognized or point to unexpected URLs.
    Rotate session tokens and credentials for any users who may
have triggered the "Connect your account" flow on a shared
workflow with an externally-registered resolver.

These workarounds do not fully remediate the risk and should
only be used as short-term mitigation measures.


Severity
High
8.5/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required High
User interaction Active
Vulnerable System Impact Metrics
Confidentiality High
Integrity High
Availability High
Subsequent System Impact Metrics
Confidentiality High
Integrity Low
Availability None
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:L/SA:N

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @nlgbao1340 nlgbao1340 Reporter
_____________________________________________________________________


Path Traversal in the n8n Node Redirects Public API Calls to
Unintended Resources

High
Matsuuu published GHSA-89p4-6h98-c7xm

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

The built-in n8n node built its Public API request paths from a
caller-supplied resource id without encoding or validating it, so
a crafted id could redirect the call to a different resource while
still using the stored API key. Where a workflow binds that id to
untrusted input, an unauthenticated caller could read, modify or
delete workflows and executions outside the intended scope, and
reach a credential's secret by repointing a live workflow. Impact
stays within the resource types the key already has scope for.

Patches

The issue has been fixed in n8n versions 1.123.80, 2.39.6, and
2.40.1. Users should upgrade to one of these versions or later
to remediate the vulnerability.

Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit all workflows that use the n8n node and ensure that
ID fields are not bound to expressions sourced from untrusted
or externally supplied input.
    Restrict or disable public webhook endpoints that feed into
workflows using the n8n node until the instance is patched.
    Review and rotate any API credentials that may have been
exposed via workflows using the n8n node with expression-bound
ID fields.

These workarounds do not fully remediate the risk and should
only be used as short-term mitigation measures.


Severity
High
8.1/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity High
Availability Low
Subsequent System Impact Metrics
Confidentiality None
Integrity None
Availability None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:P

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @nlgbao1340 nlgbao1340 Reporter

_____________________________________________________________________


Wekan and Baserow Credentials Leak Account Password to Unvalidated
Host via preAuthentication Hook

High
Matsuuu published GHSA-gx6g-2hm7-c4xf

Package
n8n (npm)

Affected versions
< 2.40.1
< 2.39.6

Patched versions
>= 2.40.1
>= 2.39.6


Description

Impact

The Wekan and Baserow username-and-password credentials send the
account username and password, unencrypted, to a URL taken from
the credential's own host field, on a path the "Allowed HTTP
Request Domains" setting did not cover. Anyone able to edit that
field — including a user who may edit credentials but not read
them — could receive the real password at a host of their choosing,
leaving no trace in execution data.
Patches

The issue has been fixed in n8n version 2.40.1 and 2.39.6. Users
should upgrade to this version or later to remediate the
vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit and revoke any custom roles that carry credential:update
from users who do not require it.
    Review Wekan and Baserow credential host/URL fields for
unexpected values and rotate any credentials that may have been
exposed.
    Monitor outbound network traffic from the n8n instance for
unexpected connections originating from credential resolution.

These workarounds do not fully remediate the risk and should
only be used as short-term mitigation measures.


Severity
High
7.1/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required Low
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity Low
Availability None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @nlgbao1340 nlgbao1340 Reporter
_____________________________________________________________________

Path Traversal and Query Injection via the Supabase Node Table Name
High
Matsuuu published GHSA-rqch-9jrh-cr8w

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

The Supabase node inserted the tableId parameter into the request
path without validation, and the parameter accepts expressions, so
it could be bound to untrusted input. A traversal sequence reached
Supabase's Auth and Storage APIs carrying the administrative
serviceRole key, which bypasses Row Level Security; a query separator
let injected text widen column projections and row filters, including
on update and delete. All five row operations are affected.

Only workflows that bind tableId to untrusted input are exploitable.


Patches

The issue has been fixed in n8n versions 1.123.80, 2.39.6, and 2.40.1.
Users should upgrade to one of these versions or later to remediate
the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should consider
the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit all workflows using the Supabase node and ensure the table
name parameter is not bound to an expression referencing external or
untrusted input.
    Disable the Supabase node by adding n8n-nodes-base.supabase to the
NODES_EXCLUDE environment variable if it is not required.
    Rotate the Supabase serviceRole key for any instance where a
vulnerable workflow configuration may have been exposed.

These workarounds do not fully remediate the risk and should only be
used as short-term mitigation measures.


Severity
High
7.1/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality Low
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity High
Availability High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @Nora-Qiu Nora-Qiu Reporter
_____________________________________________________________________

Path Traversal in Signed Resume URL Generation Enables Cross-Project
Approval Forgery

High
Matsuuu published GHSA-597w-c3jh-g8fg

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

The signed resume URL for a Send-and-Wait approval interpolated a
caller-controlled node ID, and traversal sequences in it were
resolved before signing. The signature covered only the path and
query, with nothing binding it to the originating workflow, project
or owner — so anyone able to save a workflow could mint a valid
approval URL for a gate in a project they cannot read, in either
direction, and it stayed valid for every future execution.


Patches

The issue has been fixed in n8n versions 1.123.80, 2.39.6, and
2.40.1. Users should upgrade to one of these versions or later
to remediate the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit active Send-and-Wait workflows and monitor their
execution history for unexpected approval or decline events.
    Limit workflow-creation permissions to users who require
them.

These workarounds do not fully remediate the risk and should
only be used as short-term mitigation measures.


Severity
High
7.0/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required Low
User interaction None
Vulnerable System Impact Metrics
Confidentiality None
Integrity High
Availability None
Subsequent System Impact Metrics
Confidentiality None
Integrity High
Availability None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @tr4ce-ju tr4ce-ju Reporter

_____________________________________________________________________

SQL Injection in Oracle Database Node Delete Table Drop Operation
High
Matsuuu published GHSA-4wf3-rgqr-xcp3

Package
n8n (npm)

Affected versions
< 2.40.1
< 2.39.6
< 1.123.80

Patched versions
>= 2.40.1
>= 2.39.6
>= 1.123.80


Description

Impact

The Oracle Database node's Delete Table → Drop operation inserts the
table and schema values into a dynamically built PL/SQL statement
without neutralising single quotes, so a quote in either field appends
attacker-chosen SQL to what runs. Both fields can be bound to upstream
data by expression. Where one is bound to an untrusted source, whoever
controls that data can run DDL or DML against the connected database,
bounded by the credential's privileges — demonstrated as the
unrecoverable drop of an arbitrary table. No confidentiality impact
was shown.


Patches

The issue has been fixed in n8n versions 1.123.80, 2.39.6, and 2.40.1.
Users should upgrade to one of these versions or later to remediate
the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should consider
the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit Oracle Database node workflows and ensure the table and
schema fields are not bound to untrusted external data sources.
    Disable the Oracle Database node by adding
n8n-nodes-base.oracleDatabase to the NODES_EXCLUDE environment
variable if it is not required.
    Restrict the Oracle credential used by affected workflows to
the minimum necessary privileges.

These workarounds do not fully remediate the risk and should only
be used as short-term mitigation measures.


Severity
High
7.0/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity High
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality None
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality None
Integrity High
Availability High
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @mtholmquist mtholmquist Reporter
_____________________________________________________________________


Credential Test Endpoint Resolves Project-Scoped Variables from
Attacker-Controlled Project ID

High
Matsuuu published GHSA-7gvh-q9w3-wqqx

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

The endpoint that tests a credential took the project used to
resolve workflow variables from the request body, with no check
that the caller may access that project. Because expressions in
a credential's fields are evaluated, and the credential type's
test request sends to a destination the caller chooses, an ordinary
member could name any project, have that project's variables
interpolated into the request, and read them off a host they
control.


Patches

The issue has been fixed in n8n versions 1.123.80, 2.40.1 and
2.39.6. Users should upgrade to one of these versions or later
to remediate the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit project-scoped variables for sensitive values and
rotate any credentials stored there.
    Monitor outbound HTTP traffic from the n8n instance for
unexpected destinations.

These workarounds do not fully remediate the risk and should only
be used as short-term mitigation measures.


Severity
High
7.1/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required Low
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality Low
Integrity None
Availability None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @Hemalv02 Hemalv02 Reporter
_____________________________________________________________________


Community Package Install Validation Bypass via PubSub in Queue Mode
Deployments

High
Matsuuu published GHSA-fmmv-p585-7c8x

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

In deployments using Redis for scaling (queue mode), the internal
handler that installs a community package applied none of the checks
the normal install path performs — name and prefix validation, the
install-permission check, checksum verification, and the npm safety
check. Anyone able to write to that Redis instance could have n8n
download, install and load any npm package on every instance in the
cluster, with no n8n account, while that action is otherwise
restricted to the instance owner.


Patches

The issue has been fixed in n8n versions 1.123.80, 2.39.6, and 2.40.1.
Users should upgrade to one of these versions or later to remediate
the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict access to the Redis instance to only trusted n8n
components, using authentication and network-level controls
(firewall rules, private networking).
    Disable community package installation by setting
N8N_COMMUNITY_PACKAGES_ENABLED=false if community nodes are not
required.
    Audit installed community packages for any unexpected
entries and remove them.
    Restrict n8n instance access to fully trusted users only.

These workarounds do not fully remediate the risk and should
only be used as short-term mitigation measures.


Severity
High
7.5/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Adjacent
Attack Complexity Low
Attack Requirements Present
Privileges Required Low
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity High
Availability High
Subsequent System Impact Metrics
Confidentiality None
Integrity None
Availability None
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @AyushParkara AyushParkara Reporter
_____________________________________________________________________

NoSQL Injection in MongoDB Chat Memory Node Allows Unauthenticated
Cross-Session Chat History Disclosure

High
Matsuuu published GHSA-w24g-6454-7w7f

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

The MongoDB Chat Memory node accepted the sessionId value from the
Chat Trigger request body without validating that it was a plain
string before passing it to the MongoDB query that loads
conversation history. An unauthenticated caller could supply a
MongoDB query operator in place of a session identifier, causing
the database to match sessions other than their own. This allowed
an outside visitor with access only to the public chat URL to read
conversation histories belonging to other users. The same query
path is used for write and delete operations, so those are exposed
by the same defect.

The issue affects workflows that combine a Chat Trigger node
configured with no authentication and a MongoDB Chat Memory
node.


Patches

The issue has been fixed in n8n version 1.123.80, 2.39.6 and
2.40.1. Users should upgrade to this version or later to remediate
the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Enable authentication on any Chat Trigger nodes that are backed
by a MongoDB Chat Memory node, so that the public endpoint is no
longer unauthenticated.
    Replace the MongoDB Chat Memory node with an alternative memory
backend until the instance is patched.

These workarounds do not fully remediate the risk and should only
be used as short-term mitigation measures.


Severity
High
7.0/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality Low
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity Low
Availability Low
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @trap-bytes trap-bytes Reporter


_____________________________________________________________________

Supabase Node Filters (String) Mode Allows PostgREST Filter Injection
High
Matsuuu published GHSA-xrqg-3xcp-h45x

Package
n8n (npm)

Affected versions
< 1.123.80
< 2.40.1
< 2.39.6

Patched versions
>= 1.123.80
>= 2.40.1
>= 2.39.6


Description

Impact

The Supabase node's "Filters (String)" mode inserted its field into the
query sent to the database with no escaping, and the field accepts
expressions. Where a workflow builds it from untrusted input, whoever
controls that input could widen the filter beyond the intended row:
reading every row in the table, updating them all, or deleting them all.
Confirmed for read and for delete, where a single request emptied the
table.


Patches

The issue has been fixed in n8n versions 1.123.80, 2.39.6, and 2.40.1.
Users should upgrade to one of these versions or later to remediate
the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should consider
the following temporary mitigations:

    Audit all workflows using the Supabase node's Filters (String) mode
and identify any where the filter value is built from an expression
referencing external or untrusted data.

    Replace Filters (String) with the Build Manually filter mode, which
uses parameterized filter construction and is not affected by this issue.

    Restrict access to any workflow triggers (e.g. webhooks) that feed
untrusted data into a Supabase Filters (String) field.

    Restrict n8n instance access to fully trusted users only.

These workarounds do not fully remediate the risk and should only be
used as short-term mitigation measures.

Severity
High
7.1/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality None
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity High
Availability High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @kemrec kemrec Reporter
_____________________________________________________________________


Duplicate Node IDs Bypass Workflow Credential Tamper Guard, Exposing
Credentials to a Shared Workflow Editor

High
Matsuuu published GHSA-7gjv-rcf8-x5qc

Package
n8n (npm)

Affected versions
< 1.123.80

Patched versions
>= 1.123.80


Description

Impact

Workflows shared with an editor keep credential-bearing nodes read-only,
reverting on save any node that references a credential the editor
cannot access. The revert matched nodes by id while the runtime matches
them by name, so of two nodes sharing an id only one was reverted — the
other kept the editor's parameters and the victim's credential reference,
letting them send the secret to a host they control.


Patches

The issue has been fixed in n8n version 1.123.80. Users should upgrade to
this version or later to remediate the vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should consider
the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit shared workflows and remove the Editor role from any users who
do not require it.
    Review workflow nodes for unexpected credential references or external
URLs and rotate any credentials that may have been exposed.

These workarounds do not fully remediate the risk and should only be used
as short-term mitigation measures.


Severity
High
7.1/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality Low
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity High
Availability High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H

CVE ID
No known CVE

Weaknesses
No CWEs

Credits

    @evgind evgind Reporter
_____________________________________________________________________

Inline Agent Node-Tool Introspection Decrypts Any Instance Credential
Without Ownership Check

High
Matsuuu published GHSA-9rhv-fhr8-7q5r
Package
n8n (npm)

Affected versions
< 2.40.1
< 2.39.6

Patched versions
>= 2.40.1
>= 2.39.6


Description

Impact

Registering a node tool on an inline agent resolved the tool's input
schema before the language model was consulted, and that resolution
decrypted and used whatever credential the caller named, with no
check that the caller's project owns it. The equivalent check exists
on the invocation path. An ordinary member could therefore name any
credential id on the instance — including the instance owner's — and
have its plaintext secret sent to a host of their choosing. Credential
ids are not secret: they appear in workflow JSON, exports and editor
URLs.


Patches

The issue has been fixed in n8n versions 2.39.6 and 2.40.1. Users
should upgrade to one of these versions or later to remediate the
vulnerability.


Workarounds

If upgrading is not immediately possible, administrators should
consider the following temporary mitigations:

    Restrict n8n instance access to fully trusted users only.
    Audit inline agent workflow configurations for unexpected tool
node credential references and remove any that are not recognized.
    Rotate any credentials whose IDs may have been exposed through
workflow JSON, exports, editor URLs, or API responses visible to
untrusted members.

These workarounds do not fully remediate the risk and should only
be used as short-term mitigation measures.


Severity
High
8.3/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required Low
User interaction None
Vulnerable System Impact Metrics
Confidentiality High
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity None
Availability None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

CVE ID
No known CVE

Weaknesses
No CWEs


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




