PT-2026-84998 · N8N · N8N
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.35.4
n8n versions 2.36.x prior to 2.36.2
Description
Insufficient validation of credential references in the inline workflow JSON of nodes that execute inline sub-workflows, such as the Workflow Tool node, allows a shared-workflow editor or any user interacting via the REST API, Public API, or MCP to persist a node referencing a credential they do not own. If the workflow is executed by an identity that possesses the referenced credential, the inline sub-workflow can resolve the secret and transmit it to an external endpoint controlled by an attacker, leading to credential exfiltration.
Recommendations
Update n8n to version 2.35.4 or later.
Update n8n versions 2.36.x to 2.36.2 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N