Thehackernews
Leaked n8n API Keys Lead to Encryption Key Compromise
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A security analysis revealed that leaked n8n API keys can lead to the compromise of the N8N_ENCRYPTION_KEY, which is critical for securing stored credentials and session tokens. The research identified three weaknesses in n8n's trust model, including a flawed derivation method for signing secrets that reduces effective entropy. An attack exploiting CVE-2026-25053 demonstrated how a privileged API key could escalate access to the encryption key. The analysis found 129 instances of n8n using known weak keys, highlighting the risk of credential theft. As of August 2026, n8n has received 48 CVEs since January, with several allowing attackers to escape the workflow execution environment. This situation underscores the vulnerabilities in agentic automation systems, where a single compromised key can have widespread consequences.
Key Points: • Leaked n8n API keys can lead to the compromise of critical encryption keys. • CVE-2026-25053 allows escalation from API key access to encryption key theft. • 129 instances of n8n were found using known weak encryption keys.