Credential Exposure in n8n Affects Strapi, SeaTable, and Mailcheck Nodes
CVE-2026-85171
7.1HIGH
What is CVE-2026-85171?
n8n versions prior to 1.123.73, 2.35.4, and 2.36.2 present a credential exposure risk within the Strapi, SeaTable, and Mailcheck nodes. The issue arises when decrypted credentials are transmitted to the authentication endpoint via a legacy HTTP helper, without adequate error handling. Consequently, plaintext secrets may be logged in execution error data, allowing any authenticated user to potentially access these plaintext credentials through the REST API. This vulnerability circumvents the applied redaction measures of the credentials API, making it essential for users to upgrade to the latest version to mitigate risks.
Affected Version(s)
n8n 0 < 1.123.73
n8n 0 < 2.36.2
n8n 0 < 2.35.4
