CyberRota Analysis
AI-GeneratedVersions of n8n prior to 1.123.64 are vulnerable due to improper masking of custom HTTP header credentials, which results in plaintext API keys and secrets being stored in workflow execution records. This exposure allows authenticated users with access to execution data to read sensitive information, potentially leading to unauthorized access or data breaches. Organizations using n8n should prioritize updating to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
Related CVEs
Other vulnerabilities affecting the same vendor(s)