Workflow Automation Platform Vulnerability in n8n from n8n-io
CVE-2026-54304
7.1HIGH
What is CVE-2026-54304?
An issue in the n8n workflow automation platform allows authenticated users with the right permissions to create or modify workflows to potentially exfiltrate sensitive credentials. Specifically, if the user has access to a SecurityScorecard credential with restricted domains, they can manipulate the SecurityScorecard node's report download operation to send requests to a malicious URL. This results in sending the SecurityScorecard API token to an attacker-controlled host, thus bypassing configured security measures. The vulnerability has been addressed in versions 1.123.55, 2.25.7, and 2.26.1.
Affected Version(s)
n8n < 1.123.55 < 1.123.55
n8n >= 2.26.0, < 2.26.1 < 2.26.0, 2.26.1
n8n >= 2.0.0-rc.0, < 2.25.7 < 2.0.0-rc.0, 2.25.7
