n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported. | |
| Title | n8n before 1.123.64 Credential Exposure via LLM Node Execution Data | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-22T11:21:39.365Z
Updated: 2026-07-23T13:53:56.061Z
Reserved: 2026-07-22T10:45:44.832Z
Link: CVE-2026-65589
Updated: 2026-07-23T13:52:04.040Z
No data.
No data.