CVE-2026-65589 Details
Description
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
A vulnerability exists in n8n versions prior to 1.123.64, as well as in versions 2.29.8 and 2.30.1, where custom HTTP header credentials for certain LLM sub-nodes are not properly masked. This flaw allows plaintext API keys and secrets to be written into workflow execution records. Authenticated users with access to this execution data can read the exposed header values and credentials, which persist in the database and can be exported. The issue affects workflows that use LLM sub-nodes with custom headers defined in their credentials.
Users should upgrade to n8n versions 1.123.64, 2.29.8, or 2.30.1 or later. If an immediate upgrade is not possible, access to execution data should be restricted to trusted users, custom headers in LLM node credentials should be avoided, and any API keys or secrets that may have been exposed should be rotated.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-89gh-3pgc-v5h2 | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-credential-exposure-via-llm-node-execution-data | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.64 >= 2.0.0, < 2.29.8 2.30.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |