CVE-2026-59254

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node expressions without requiring explicit secrets access permissions.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2026, 12:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 12:18

Updated : 2026-07-15 18:20


NVD link : CVE-2026-59254

Mitre link : CVE-2026-59254

CVE.ORG link : CVE-2026-59254


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key