SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65589

MEDIUM · CVSS 6.5 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Versions of n8n prior to 1.123.64 are vulnerable due to improper masking of custom HTTP header credentials, which results in plaintext API keys and secrets being stored in workflow execution records. This exposure allows authenticated users with access to execution data to read sensitive information, potentially leading to unauthorized access or data breaches. Organizations using n8n should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65589
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%

Original NVD Description

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.

Related CVEs

Other vulnerabilities affecting the same vendor(s)