Executive brief
n8n is a workflow automation platform. This vulnerability allows authenticated users with project editor access to read sensitive external secrets (such as API keys and credentials stored outside the main vault) by referencing them in workflow node expressions, bypassing intended access controls. An attacker with editor permissions on a project could extract plaintext secret values without needing explicit secrets management permissions, potentially compromising credentials used by automated workflows.
Technical details
This is an information disclosure vulnerability (CWE-639: Authorization Bypass Through User-Controlled Key) in n8n's expression evaluation system. The root cause is that external secrets are incorrectly resolved and made accessible in workflow node expressions where they are not intended to be available. An authenticated user with project editor role can exploit this by crafting workflow node expressions that reference external secrets, extracting their plaintext values without requiring dedicated secrets access permissions. The vulnerability is reachable over the network and requires authentication (low privilege level), but no user interaction. The attack impacts confidentiality of subsequent systems (external systems using those secrets). Patches are available in n8n 2.27.4 and 2.28.1; users should upgrade immediately. Temporary mitigations include restricting project membership to trusted users and limiting editor access on instances where external secrets are configured.
Affected products
- n8n n8n < 2.27.4, < 2.28.1
Timeline
- 2026-06-24: disclosed
- 2026-06-24: patched: Patches released in versions 2.27.4 and 2.28.1