n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-89gh-3pgc-v5h2 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-credential-exposure-via-llm-node-execution-data | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-22 12:18
Updated : 2026-07-27 19:09
NVD link : CVE-2026-65589
Mitre link : CVE-2026-65589
CVE.ORG link : CVE-2026-65589
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-532
Insertion of Sensitive Information into Log File
