GHSA-fmvg-vhqq-r2mjMedium▾ SunlitDuplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-89gh-3pgc-v5h2. This link is maintained to preserve external references.
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
n8n < 1.123.64Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65589Mediumn8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-85171Medium· 6.5n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform
CVE-2026-86085Medium· 4.9n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform