Credential Exposure in n8n Affects Strapi, SeaTable, and Mailcheck Nodes
CVE-2026-85171

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85171?

n8n versions prior to 1.123.73, 2.35.4, and 2.36.2 present a credential exposure risk within the Strapi, SeaTable, and Mailcheck nodes. The issue arises when decrypted credentials are transmitted to the authentication endpoint via a legacy HTTP helper, without adequate error handling. Consequently, plaintext secrets may be logged in execution error data, allowing any authenticated user to potentially access these plaintext credentials through the REST API. This vulnerability circumvents the applied redaction measures of the credentials API, making it essential for users to upgrade to the latest version to mitigate risks.

Affected Version(s)

n8n 0 < 1.123.73

n8n 0 < 2.36.2

n8n 0 < 2.35.4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Masofgon
.