Incorrect authorization in n8n - #VU150759
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose credentials.
The vulnerability exists due to improper authorization in the workflow credential tamper guard when saving a shared workflow containing nodes with duplicate IDs. A remote attacker can create nodes sharing an ID to disclose credentials.
Exploitation requires a workflow shared with an editor.