PT-2026-78932 · N8N · N8N
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.69
n8n versions prior to 2.33.4
n8n versions prior to 2.34.1
Description
The GraphQL node fails to properly handle connection-level errors, re-throwing the underlying HTTP client error without wrapping it in the standard error type. This error includes the live request headers, which contain a decrypted credential secret. Because the execution engine persists this data verbatim, any authenticated user with access to the execution logs can retrieve the decrypted credential secret.
Recommendations
Update to version 1.123.69 or later.
Update to version 2.33.4 or later.
Update to version 2.34.1 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N