Beveiligingsadvies

CVE-2026-59209

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-09 15:32:27
Laatst bijgewerkt 2026-07-09 17:28:23
Toegewezen door GitHub_M
CVSS-score 7.1
Status PUBLISHED

Beschrijving

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination expression and exfiltrate the secret through item data. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.