Improper access control in n8n - CVE-2026-54304
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the SecurityScorecard node report download operation when handling a user-supplied URL. A remote user can configure an attacker-controlled URL to cause the SecurityScorecard API token to be sent to an external host and disclose sensitive information.
Exploitation requires permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains.