Information Exposure Through an Error Message in n8n - #VU140996
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper handling of raw error data in the GraphQL node when processing failed connection-level requests. A remote user can read a stored execution containing the unwrapped HTTP client error to disclose sensitive information.
The persisted error data may include live request headers containing a decrypted credential secret.