Executive brief
n8n is a workflow automation platform that enables users to connect various business applications and automate repetitive tasks. A flaw in the Strapi, SeaTable, and Mailcheck integration nodes causes decrypted credentials to be stored in plaintext within execution error logs. Any authenticated user can retrieve these credentials through the REST API, potentially gaining unauthorized access to connected third-party services and compromising integrated systems.
Technical details
The vulnerability is a credential exposure flaw (CWE-532: Insertion of Sensitive Information into Log File) affecting the Strapi, SeaTable, and Mailcheck nodes in n8n. These nodes send decrypted credentials to authentication endpoints via a legacy HTTP helper without proper error handling, causing plaintext secrets to be persisted in execution error data. An authenticated attacker with REST API access can retrieve these stored credentials from their own execution history, bypassing the blank-value redaction that n8n's standard credentials API enforces. The issue requires authentication and network access to the n8n instance. Patches are available in versions 1.123.73, 2.35.4, and 2.36.2.
Affected products
- n8n n8n before 1.123.73, 2.35.4, and 2.36.2
Timeline
- 2026-08-19: disclosed: GitHub Security Advisory GHSA-vrv8-j27g-g7cr published
- 2026-09-03: advisory: CVE-2026-85171 assigned and published
- 2026-09-03: patched: Patches released in versions 1.123.73, 2.35.4, and 2.36.2