PT-2026-63347 · N8N · N8N
CVE-2026-65589
·
Published
2026-07-22
·
Updated
2026-07-22
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.64
Description
Custom HTTP header credentials used in LLM sub-nodes, such as OpenAI, Anthropic, and Lemonade, are not properly masked during execution. While these values appear masked in the user interface, they are written in plaintext to workflow execution records. Authenticated users with access to this execution data can read sensitive information, such as API keys and secrets, which are persisted in the database and can be exported.
Recommendations
Update to version 1.123.64, 2.29.8, 2.30.1, or later.
Restrict access to execution data to fully trusted users only.
Avoid configuring custom headers in LLM node credentials and use alternative authentication mechanisms.
Rotate any API keys or secrets that may have been stored as custom header values in affected credentials.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N