Executive brief
n8n is a workflow automation platform that allows users to build and execute automations combining visual design with custom code. An authentication bypass vulnerability allows project editors to read plaintext values of external secrets by referencing them directly in workflow node expressions, even without explicit permission to access those secrets. This enables unauthorized disclosure of sensitive credentials and API keys stored in external secret management systems.
Technical details
The vulnerability is an authorization bypass (CWE-639) in n8n's workflow expression engine where external secrets are incorrectly resolved in node expressions outside their intended credentials scope. An authenticated user with project editor role access can reference external secrets by name in workflow node expressions to retrieve their plaintext values, bypassing the intended secrets access control layer that would normally prevent such access. The attack requires network connectivity to the n8n instance, valid project editor credentials, and the instance must have the external secrets feature configured. The vulnerability affects all versions prior to 2.27.4 and 2.28.0 (with 2.28.1 being the fixed version). Patches have been released in n8n 2.27.4 and 2.28.1.
Affected products
- n8n n8n all versions before 2.27.4 and 2.28.0 through 2.28.0
Timeline
- 2026-06-24: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-2434-3x6q-8r99
- 2026-06-24: patched: Fixed in n8n 2.27.4 and 2.28.1
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-2434-3x6q-8r99
- https://github.com/n8n-io/n8n
- https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4
- https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1
- https://www.vulncheck.com/advisories/n8n-external-secrets-disclosure-via-workflow-node-expressions