Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-65589

17 дней назад

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-89gh-3pgc-v5h2

16 дней назад

n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65589

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.

CVSS3: 6.5
0%
Низкий
17 дней назад
github логотип
GHSA-89gh-3pgc-v5h2

n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

0%
Низкий
16 дней назад

Уязвимостей на страницу