CVE-2026-85171

Summary

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper outside any error handling, causing the plaintext secret to be persisted in execution error data. Any authenticated user can read the plaintext secret from their own execution through the REST API, bypassing the blank-value redaction enforced by the credentials API.

Affected Software

VendorProductVersion RangeStatus
n8n-ion8n0 < 1.123.73affected
n8n-ion8n1.123.73unaffected
n8n-ion8n0 < 2.36.2affected
n8n-ion8n2.36.2unaffected
n8n-ion8n0 < 2.35.4affected
n8n-ion8n2.35.4unaffected

Weaknesses

  • CWE-532: Insertion of Sensitive Information into Log File

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References