CVE-2026-59209
EUVD-2026-4261309.07.2026, 17:17
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination expression and exfiltrate the secret through item data. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| n8n | n8n | 𝑥 < 1.123.61 |
| n8n | n8n | 𝑥 < 1.123.61 |
| n8n | n8n | 2.0.0 ≤ 𝑥 < 2.27.4 |
| n8n | n8n | 2.0.0 ≤ 𝑥 < 2.27.4 |
| n8n | n8n | 2.28.0 |
| n8n | n8n | 2.28.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration