PatchSiren cyber security CVE debrief
CVE-2026-65589 n8n-io CVE debrief
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data. This oversight results in the writing of plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported. The vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity.
- Vendor
- n8n-io
- Product
- n8n
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of n8n versions before 1.123.64 should be aware of this vulnerability, especially those with multi-user environments or workflows involving sensitive data in custom HTTP headers. It is crucial for administrators to assess their exposure and take necessary actions to mitigate the risk.
Technical summary
The vulnerability arises from inadequate masking of custom HTTP header credentials during LLM sub-node execution in n8n workflows. This allows authenticated users to access sensitive information, including API keys and secrets, from workflow execution records stored in the database. The issue affects n8n versions before 1.123.64, posing a Medium severity risk with a CVSS score of 5.1. Users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
Defensive priority
Medium priority due to the requirement for authentication and access to execution data. However, the impact can be significant in multi-user environments or when sensitive data is involved in workflows. Therefore, it is essential to address this vulnerability promptly and apply the recommended actions to prevent potential exploitation.
Recommended defensive actions
- Upgrade to n8n version 1.123.64 or later
- Review and update workflows using LLM sub-nodes with custom HTTP headers
- Restrict access to execution data for authenticated users
- Monitor for suspicious activity related to workflow execution records
- Perform a thorough review of existing workflows for potential exposure
- Inventory and track all systems using n8n for potential remediation
- Implement additional monitoring for sensitive data exposure in workflow execution records
Evidence notes
The CVE record was published on 2026-07-22T12:18:18.857Z and was last modified on 2026-07-22T16:27:18.220Z. The NVD entry is currently Undergoing Analysis. This information is based on the provided source corpus and may not reflect the current status. Users should verify the information with the official sources for the most up-to-date details.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T12:18:18.857Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.