Credentials Leak Vulnerability in n8n by n8n-io
CVE-2026-103256
7.1HIGH
What is CVE-2026-103256?
n8n prior to version 2.39.6 and versions 2.40.0 leading up to 2.40.1 are susceptible to a credential leak vulnerability. This issue allows unencrypted username-and-password credentials associated with Wekan and Baserow to be sent to unvalidated hosts. Attackers who possess permissions to update credentials can manipulate the host field, facilitating the capture of accounts' passwords by redirecting them to arbitrary hosts, thus evading any domain validation controls that may be in place.
Affected Version(s)
n8n 0 < 2.39.6
n8n 2.40.0 < 2.40.1
