www.vulncheck.com N8n Vulnerabilities Lead to Credential Disclosure and Tampering Risks
Article Content
Browse articles
- •Two vulnerabilities in n8n affect multiple versions, risking credential exposure and tampering.
- •Users are urged to upgrade to n8n version 2.40.1 or later and 1.123.80 to prevent issues.
- •No confirmed active exploitation of these vulnerabilities has been reported.
Two vulnerabilities have been identified in n8n, affecting versions before 2.39.6 and 2.40.x before 2.40.1, and versions before 1.123.80. The first vulnerability allows credential disclosure via node-tool introspection, categorized as CWE-639, with GitHub Security Advisory GHSA-9rhv-fhr8-7q5r. The second vulnerability involves credential tampering due to duplicate node IDs. Both vulnerabilities could potentially expose sensitive information and allow unauthorized access. Users are advised to upgrade to the latest versions to mitigate these risks. No has been reported at this time.
Ask AI about this cluster
Answers cite the sources they use
Updated 1h ago How this analysis works
More articles in this cluster (2)
Common questions
Which versions are affected?
n8n versions before 2.39.6 and 2.40.x before 2.40.1, as well as versions before 1.123.80.
Is there any active exploitation reported?
No active exploitation has been reported for these vulnerabilities at this time.
What should users do to protect themselves?
Users should upgrade to n8n version 2.40.1 or later and 1.123.80 to mitigate the vulnerabilities.
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…