Skip to content
n8nGHSA-pmqw-72cg-wx85

n8n: Credential Exfiltration via Permission Bypass

High9.6CVE-2026-54307 · Published Jun 16, 2026 · updated Jul 8, 2026

## Impact A member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor. ## Patches The issue has been fixed in n8n versions 1.123.55, 2.25.7, and 2.26.2. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict workflow sharing to fully trusted users only. - Audit shared workflows for unexpected credential references or recent modifications. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures. --- n8n has adopted CVSS 4.0 as primary score for all security advisories. CVSS 3.1 vector strings are provided for backwards compatibility. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

GitHub advisory

Affected versions

PackageAffectedFixed in
n8n
npm
< 1.123.551.123.55
>= 2.26.0, < 2.26.22.26.2
>= 2.0.0-rc.0, < 2.25.72.25.7
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
CVE-2026-54307

More n8n advisories

All n8n
Advisory
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
High7.7Jun 16
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
High10.0Jun 16
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
High9.9Jun 16
n8n: Denial of Service via ZIP decompression in webhook workflow
Medium5.9Jun 16
n8n: Public API Execution Retry Authorization Bypass
Medium6.4Jun 16
n8n: Python Code Node AST Validator Bypass
Medium5.0Jun 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.