CVE-2026-85171: n8n before 1.123.73 Credential Exposure via Error Logging

Published Sep 3, 2026
·
Updated

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper outside any error handling, causing the plaintext secret to be persisted in execution error data. Any authenticated user can read the plaintext secret from their own execution through the REST API, bypassing the blank-value redaction enforced by the credentials API.

Affected Software

1 affected component
n8n<1.123.73, =2.35.4, =2.36.2

Event History

Sep 3, 2026
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
DescriptionWeakness

Frequently Asked Questions

1

Which users can retrieve exposed credentials?

Any authenticated user can read the plaintext secret from their own execution through the REST API. The issue bypasses the blank-value redaction normally applied by the credentials API.

2

What must occur for a credential to be recorded in execution error data?

A Strapi, SeaTable, or Mailcheck node must send decrypted credentials to its authentication endpoint using the raw legacy HTTP helper, and the resulting failure must be stored as execution error data. The plaintext secret is then persisted in that error data.

3

Which releases are affected?

Affected releases are n8n versions before 1.123.73, 2.35.4, and 2.36.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203