PT-2026-63347 · N8N · N8N

CVE-2026-65589

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64
Description Custom HTTP header credentials used in LLM sub-nodes, such as OpenAI, Anthropic, and Lemonade, are not properly masked during execution. While these values appear masked in the user interface, they are written in plaintext to workflow execution records. Authenticated users with access to this execution data can read sensitive information, such as API keys and secrets, which are persisted in the database and can be exported.
Recommendations Update to version 1.123.64, 2.29.8, 2.30.1, or later. Restrict access to execution data to fully trusted users only. Avoid configuring custom headers in LLM node credentials and use alternative authentication mechanisms. Rotate any API keys or secrets that may have been stored as custom header values in affected credentials.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65589
GHSA-89GH-3PGC-V5H2

Affected Products

N8N