Credential Exfiltration Vulnerability in n8n Workflow Automation Tool
CVE-2026-72763
7.2HIGH
What is CVE-2026-72763?
The n8n workflow automation tool has a vulnerability that allows malicious users with Editor access to indirectly exfiltrate credentials. This issue arises from the inadequate validation of credentials located inside an Execute Sub-workflow node's inline JSON. When a user familiar with a target credential's ID constructs inline JSON reference, it bypasses validation checks, potentially exposing sensitive credential data in the parent workflow's context. This poses significant security risks for organizations utilizing shared workflows.
Affected Version(s)
n8n 0 < 1.123.67
n8n 0 < 2.32.1
n8n 0 < 2.31.5
