Junglewise Threat Intelligence

n8n information disclosure via external secrets in workflow expressions

Severity: medium · CVSS 6.3 · Published 2026-07-15

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform used to connect various business applications and services. A security flaw allowed users with 'editor' permissions to view sensitive external secrets (such as API keys or passwords) that they were not authorized to see. This could lead to unauthorized access to third-party services integrated with the platform.

Technical details

An information disclosure vulnerability exists in n8n due to improper authorization (CWE-639) when resolving external secrets. The software incorrectly allowed external secrets to be resolved within workflow node expressions, even when those expressions were outside the designated credentials scope. An authenticated attacker with project editor privileges could exploit this by referencing secret keys in node expressions to reveal their plaintext values, bypassing explicit secret access permissions. This issue specifically affects instances where the external secrets feature is configured. The vulnerability is resolved in versions 2.27.4 and 2.28.1.

Affected products

  • n8n n8n < 2.27.4, < 2.28.1

Timeline

  • 2026-06-24: advisory: Original advisory published by n8n
  • 2026-07-15: disclosed: NVD publication date
  • 2026-07-22: other: Duplicate advisory GHSA-3j7v-fhjg-6rh2 withdrawn

References

Related threats