n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Jul 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported. | |
| Title | n8n before 1.123.64 Credential Exposure via LLM Node Execution Data | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-22T11:21:39.365Z
Reserved: 2026-07-22T10:45:44.832Z
Link: CVE-2026-65589
No data.
No data.
No data.
OpenCVE Enrichment
No data.