CVE-2026-65589
Analyzed Analyzed - Analysis Complete

n8n LLM Sub-Node Credential Exposure via Unmasked HTTP Headers

Vulnerability report for CVE-2026-65589, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-27

Assigner: VulnCheck

Description

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-27
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
n8n n8n to 1.123.64 (exc)
n8n n8n From 2.0.0 (inc) to 2.29.8 (exc)
n8n n8n to 1.123.64 (exc)
n8n n8n From 2.0.0 (inc) to 2.29.8 (exc)
n8n n8n 2.30.0
n8n n8n 2.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-65589 is a vulnerability in n8n versions before 1.123.64 where custom HTTP header credentials in LLM sub-nodes are not properly masked. This causes API keys and secrets to be written in plaintext to workflow execution records. Authenticated users with access to execution data can read these exposed credentials, which persist in the database and can be exported.

Detection Guidance

Check n8n workflow execution logs for plaintext API keys or secrets in custom HTTP headers. Search database records for exposed credentials in execution data. Review workflow configurations using LLM sub-nodes with custom headers.

Impact Analysis

This vulnerability allows attackers with access to execution data to steal API keys and other secrets. Exposed credentials may persist in the database and could be exported, leading to unauthorized access to external services. Attackers could use these credentials to make API calls, access sensitive data, or perform actions on behalf of the user.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized exposure of sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguarding protected health information. The exposure of API keys and secrets may violate these regulations, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Upgrade n8n to versions 1.123.64, 2.29.8, or 2.30.1 or later. Restrict access to execution data. Avoid using custom headers in credentials. Rotate any exposed API keys or secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65589. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart