CVE-2026-59254: n8n - External Secrets Disclosure via Workflow Node Expressions

Published Jul 15, 2026
·
Updated

Impact External secrets were incorrectly resolved in workflow node expressions, where they are not intended to be available. An authenticated user with project editor access could read the plaintext value of external secrets by referencing them in a node expression, without needing explicit secrets access permissions.

This issue only affects instances with the external secrets feature configured.

Patches The issue has been fixed in n8n versions 2.27.4 and 2.28.1. Users should upgrade to one of these versions or later to remediate the vulnerability.

Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict project membership to fully trusted users only. - Avoid granting editor access to projects on instances where external secrets are configured.

These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Other sources

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node expressions without requiring explicit secrets access permissions.

NVD

Affected Software

3 affected componentsFixes available
n8n n8n<2.28.1
npm/n8n<2.27.4
2.27.4
npm/n8n>=2.28.0<2.28.1
2.28.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/n8n to a version that resolves this vulnerability.

    Fixed in 2.27.4
  2. Upgrade

    Upgrade npm/n8n to a version that resolves this vulnerability.

    Fixed in 2.28.1
  3. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.27.4
  4. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.28.1
  5. Compensating control

    Temporary mitigation: Avoid granting editor access to projects on instances where external secrets are configured.

  6. Compensating control

    Temporary mitigation: Restrict project membership to fully trusted users only.

Event History

Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Jul 22, 2026
Advisory Published
via GitHub·10:23 PM
Data Sourced
via GitHub·10:23 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59254?

CVE-2026-59254 has a medium severity rating of 6.3 based on the CVSS score.

2

How do I fix CVE-2026-59254?

To fix CVE-2026-59254, upgrade to n8n version 2.28.1 or later where the vulnerability is resolved.

3

Who is affected by CVE-2026-59254?

Authenticated project editors using n8n before version 2.28.1 are affected by CVE-2026-59254.

4

What is the nature of CVE-2026-59254?

CVE-2026-59254 involves information disclosure where external secrets can be accessed improperly through workflow node expressions.

5

Can CVE-2026-59254 be exploited remotely?

CVE-2026-59254 requires authenticated access, meaning it can be exploited by users with editor permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203