Impact
The vulnerability enables custom HTTP header credentials to be written in clear text to LLM sub‑node execution logs. API keys and other secrets that should be masked are persisted in the database and can be exported by anyone who has permission to view workflow execution data, thereby compromising confidentiality and potentially allowing unauthorized access to third‑party services.
Affected Systems
All installations of n8n running a version older than 1.123.64 are affected. The issue is documented for the standard n8n distribution maintained by n8n‑io. Custom or proprietary builds are not explicitly listed in the advisory, so users should verify their build configurations but the vulnerability is most likely limited to the identified product and versions.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk, and the EPSS score of less than 1% suggests that active exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access to execution data, which typically limits the threat to insiders or compromised accounts rather than external attackers. Once exploited, an attacker can read and export the exposed credentials, potentially gaining unauthorized access to external services.
OpenCVE Enrichment
Github GHSA