Junglewise Threat Intelligence

n8n credential exposure in LLM node execution data

Severity: medium · CVSS 5.1 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool that allows businesses to connect different software services. A security issue was identified where sensitive information, such as API keys and secrets used in AI-related tasks (LLM nodes), was being saved in plain text within the system's activity logs. This could allow authorized users of the platform to see credentials they should not have access to, potentially leading to the unauthorized use of connected third-party services like OpenAI or Anthropic.

Technical details

n8n versions prior to 1.123.64, 2.29.8, and 2.30.1 contain a sensitive information disclosure vulnerability (CWE-532). The application fails to mask custom HTTP headers configured in credentials for specific LLM sub-nodes (e.g., OpenAI, Anthropic). While these values are masked in the user interface, they are written in plaintext into the workflow execution records stored in the database. An authenticated attacker with access to execution data can retrieve these secrets, which may persist in the database or be included in exported workflow data. The issue is resolved in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n-io n8n < 1.123.64, < 2.29.8, < 2.30.1

Timeline

  • 2026-07-08: advisory: Original advisory GHSA-89gh-3pgc-v5h2 published
  • 2026-07-22: disclosed: CVE-2026-65589 published

References

Related threats