Workflow Automation Platform Vulnerability in n8n from n8n-io
CVE-2026-54304

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54304?

An issue in the n8n workflow automation platform allows authenticated users with the right permissions to create or modify workflows to potentially exfiltrate sensitive credentials. Specifically, if the user has access to a SecurityScorecard credential with restricted domains, they can manipulate the SecurityScorecard node's report download operation to send requests to a malicious URL. This results in sending the SecurityScorecard API token to an attacker-controlled host, thus bypassing configured security measures. The vulnerability has been addressed in versions 1.123.55, 2.25.7, and 2.26.1.

Affected Version(s)

n8n < 1.123.55 < 1.123.55

n8n >= 2.26.0, < 2.26.1 < 2.26.0, 2.26.1

n8n >= 2.0.0-rc.0, < 2.25.7 < 2.0.0-rc.0, 2.25.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.