Description
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operation to target an attacker-controlled URL. The node attached the SecurityScorecard API token to the outbound request, causing the credential to be sent to the attacker-controlled host bypassing credential configured limitations and exfiltrating. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.1.
Published: 2026-06-23
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

n8n is an open‑source workflow automation platform. Until versions 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permissions to create or modify workflows and with access to a SecurityScorecard credential that has a limited set of allowed domains could configure the SecurityScorecard node’s report‑download operation to target an attacker‑controlled URL. The node automatically appends the SecurityScorecard API token to the outbound request, sending the credential to the malicious host and bypassing the configured domain restrictions. This results in exfiltration of the API token, allowing the attacker to authenticate with SecurityScorecard services and potentially access or manipulate sensitive information.

Affected Systems

The vulnerability affects installations of n8n-io:n8n prior to versions 1.123.55, 2.25.7, and 2.26.1. Any instance running a vulnerable version and employing the SecurityScorecard node is at risk.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate to high risk given the potential for credential compromise. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires a user with workflow edit permissions and legitimate access to a SecurityScorecard credential, making it a privilege‑based attack vector rather than remote unauthenticated exploitation. While the prerequisite access limits the attack surface, the impact of the token leak is significant because the credential can be used to reach external SecurityScorecard services.

Generated by OpenCVE AI on June 23, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to at least 1.123.55, 2.25.7, or 2.26.1 to apply the vendor‑provided fix
  • Limit workflow creation and editing rights to only trusted administrators to reduce the chance that an attacker can reconfigure the node
  • Review and tighten domain restrictions on SecurityScorecard credentials, ensuring that they cannot be used to request data from external hosts

Generated by OpenCVE AI on June 23, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rm2v-h48j-895m n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
History

Tue, 23 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operation to target an attacker-controlled URL. The node attached the SecurityScorecard API token to the outbound request, causing the credential to be sent to the attacker-controlled host bypassing credential configured limitations and exfiltrating. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.1.
Title n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-23T17:18:31.381Z

Reserved: 2026-06-12T17:46:37.294Z

Link: CVE-2026-54304

cve-icon Vulnrichment

Updated: 2026-06-23T17:18:27.207Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-23T22:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor