Skip to content
N8n Vulnerabilities Lead to Credential Disclosure and Tampering Risks

N8n Vulnerabilities Lead to Credential Disclosure and Tampering Risks

First seen 1 Oct 2026, 21:04 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 21:05 UTC
  • •Two vulnerabilities in n8n affect multiple versions, risking credential exposure and tampering.
  • •Users are urged to upgrade to n8n version 2.40.1 or later and 1.123.80 to prevent issues.
  • •No confirmed active exploitation of these vulnerabilities has been reported.

Two vulnerabilities have been identified in n8n, affecting versions before 2.39.6 and 2.40.x before 2.40.1, and versions before 1.123.80. The first vulnerability allows credential disclosure via node-tool introspection, categorized as CWE-639, with GitHub Security Advisory GHSA-9rhv-fhr8-7q5r. The second vulnerability involves credential tampering due to duplicate node IDs. Both vulnerabilities could potentially expose sensitive information and allow unauthorized access. Users are advised to upgrade to the latest versions to mitigate these risks. No has been reported at this time.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-01
Disclosure of vulnerabilities
n8n vulnerabilities disclosed affecting versions before 2.39.6, 2.40.x before 2.40.1, and before 1.123.80.
VulnCheck
2026-10-01
Patch released
n8n released updates to address the vulnerabilities; users are advised to upgrade immediately.
VulnCheck

More articles in this cluster (2)

Common questions

Which versions are affected?
n8n versions before 2.39.6 and 2.40.x before 2.40.1, as well as versions before 1.123.80.
Is there any active exploitation reported?
No active exploitation has been reported for these vulnerabilities at this time.
What should users do to protect themselves?
Users should upgrade to n8n version 2.40.1 or later and 1.123.80 to mitigate the vulnerabilities.