n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-89gh-3pgc-v5h2 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-credential-exposure-via-llm-node-execution-data | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
27 Jul 2026, 19:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-89gh-3pgc-v5h2 - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-before-credential-exposure-via-llm-node-execution-data - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:enterprise:node.js:*:* cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:* cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:community:node.js:*:* |
|
| First Time |
N8n
N8n n8n |
22 Jul 2026, 12:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-22 12:18
Updated : 2026-07-27 19:09
NVD link : CVE-2026-65589
Mitre link : CVE-2026-65589
CVE.ORG link : CVE-2026-65589
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-532
Insertion of Sensitive Information into Log File
