CVE-2026-59209EPSS p32.1%
CVE-2026-59209CVE-2026-59209
n8n / n8n
Description
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination expression and exfiltrate the secret through item data. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.40% probability of exploitation · percentile 32.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |