Executive brief
n8n is a workflow automation platform used to build and run integrations and business processes. An authenticated user with an API key can bypass authorization checks to read sensitive variables (such as credentials and tokens) from projects they do not have access to, potentially leading to exposure of secrets across the platform.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability in n8n's public API variables endpoint. An authenticated user with variable:list API key scope can supply an arbitrary projectId query parameter to access variables from projects they are not a member of. The vulnerability exists because the API handler queries the variables repository directly without enforcing project membership authorization checks, bypassing the authorization-aware service layer. This allows disclosure of sensitive information stored in variables, including credentials and API tokens. The issue only affects licensed enterprise or team deployments with multiple projects and the variables feature enabled. Patches are available in versions 1.123.32, 2.17.4, and 2.18.1.
Affected products
- n8n n8n all versions before 1.123.32, 2.0.0 before 2.17.4, 2.18.0 before 2.18.1
Timeline
- 2026-04-22: disclosed
- 2026-04-29: patched: patches released in versions 1.123.32, 2.17.4, and 2.18.1