Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4309 articles · 196687 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-59254EXPLOITEDPATCHED
n8n · n8n

n8n - External Secrets Disclosure via Workflow Node Expressions

Description

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node expressions without requiring explicit secrets access permissions.

Affected Products

VendorProductVersions
n8nn8nnpm/n8n: >= 2.28.0, < 2.28.1, npm/n8n: < 2.27.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
npmn8nGHSA85%

References

  • https://github.com/n8n-io/n8n/security/advisories/GHSA-2434-3x6q-8r99(vendor-advisory)
  • https://www.vulncheck.com/advisories/n8n-external-secrets-disclosure-via-workflow-node-expressions(third-party-advisory)

Related News (1 articles)

Tier C
VulDB40d ago
CVE-2026-59254 | n8n up to 2.28.0 Secrets Resolution missing encryption
→ No new info (linked only)
CVSS 3.17.5 MEDIUM
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
n8n@2.28.1n8n@2.27.4
CWECWE-639
PublishedJul 15, 2026
Last enriched40d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59259EXP
n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
MEDIUMCVE-2026-59253
n8n - Improper Authorization in Workflow Assignment to Folders
MEDIUMCVE-2026-58661
n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
NONECVE-2026-56354EXP
n8n - Cross-Site Scripting and Open Redirect in Form Node
NONECVE-2026-56360
n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: description, severity, cvssEstimate, activelyExploited
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 40d ago
v2Tier C40d ago

Updated description with new technical details, changed severity to HIGH, and updated CVSS estimate to 7.5.

descriptionseveritycvssEstimateactivelyExploited
via VulDB
v140d ago

Initial creation