Tag: n8n
4 articles

Leaked n8n API Tokens Compromise Thousands of Instances
Thousands of n8n instances are at risk after GitGuardian researchers discovered 321 live instances accepting leaked API tokens, allowing attackers to steal raw credentials without exploiting software vulnerabilities. A staggering 4,576 credentials tied to 1,255 hostnames were compromised, putting countless users at risk of data breaches.

n8n Flaw Lets Authenticated Editors Run OS Commands
A security flaw in n8n allows authenticated editors to run OS commands, thanks to two overlooked vulnerabilities that let them break free from the platform's protective sandbox. This weakness was uncovered by Security Joes' research team, who found that the flaws could be exploited to execute operating-system commands as the n8n process.

n8n Flaw Exposes User Accounts to Unauthorized Login via Token Exchange
A security flaw in n8n's workflow automation platform allowed unauthorized users to log in to accounts due to a token exchange mishap, essentially handing out the wrong accounts at login. This vulnerability stemmed from a misimplementation of the Enterprise token exchange feature.

n8n Workflow Automation Platform Exploited to Deliver Malware via Phishing Emails
Imagine a tool designed to streamline your work being turned against you - that's what happened when threat actors exploited the popular n8n workflow automation platform to deliver malware via phishing emails, starting as early as October 2025. This clever tactic uses trusted infrastructure to evade defenses, turning productivity tools into a conduit for harm.