Authorization bypass through user-controlled key in n8n - #VU150758

 

Authorization bypass through user-controlled key in n8n - #VU150758

Published: September 17, 2026


Vulnerability identifier: #VU150758
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper authorization in inline agent node-tool input schema resolution when registering a node tool on an inline agent. A remote user can specify an arbitrary instance credential ID and send its plaintext secret to a host of their choosing to disclose sensitive information.

Credential IDs may be available in workflow JSON, exports, and editor URLs.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 2.39.6, 2.40.1

External References

Related Security Bulletins