n8n Credential Exfiltration Vulnerability (CVE-2026-54304) — HIGH Severity

A significant security flaw has been discovered in n8n, an open-source platform used for automating workflows. This vulnerability, identified as CVE-2026-54304, could allow unauthorized access to sensitive API tokens. Specifically, an attacker with authenticated user access and certain permissions could trick the SecurityScorecard node into sending its API token to an external, malicious website. This bypasses any domain restrictions that might have been set up, potentially exposing critical credentials.

CVE Details

Product: n8n

Published Date: June 23, 2026

Severity: HIGH

Status: Analyzed

Affected Products

The vulnerability impacts n8n versions older than 1.123.55, 2.25.7, and 2.26.1. If you are running any version prior to these, your system is at risk.

Current Status

The vulnerability has been thoroughly analyzed, and details regarding its nature and potential impact are available.

Severity Level

This vulnerability is rated as HIGH severity, with a CVSS score of 7.7. A high severity rating indicates that the flaw could lead to a significant impact if exploited. In this case, the main concern is the potential exposure of sensitive API tokens, which could grant an attacker unauthorized access to other systems or data linked to the compromised credential.

Possible Solutions

The good news is that fixes are available. Users are strongly advised to upgrade their n8n installations to one of the following patched versions immediately:

  • n8n version 1.123.55 or later
  • n8n version 2.25.7 or later
  • n8n version 2.26.1 or later

If an immediate upgrade is not feasible, temporary mitigation steps can help reduce the risk, though they do not fully eliminate it:

  • Restrict workflow creation and editing permissions to only fully trusted administrative users.
  • Disable the SecurityScorecard node by adding n8n-nodes-base.securityScorecard to your NODES_EXCLUDE environment variable.

These workarounds should only be considered short-term measures until a full upgrade can be performed.

References

https://github.com/n8n-io/n8n/security/advisories/GHSA-rm2v-h48j-895m

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.