What is CVE-2026-65589?
A vulnerability in n8n fails to mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys to execution records. Authenticated users with access to these records can read the exposed credentials; users of versions before 1.123.64 should update immediately.
Azərbaycanca: n8n platformasında zəiflik aşkar edilib: LLM sub-node icra məlumatlarında fərdi HTTP başlıqlarında olan etimadnamələr maskalanmır, nəticədə API açarları mətn formasında qalır. Bu, icra qeydlərinə girişi olan autentifikasiyalı istifadəçilərə məxfi məlumatları oxumağa imkan verir; 1.123.64 versiyasından əvvəlki versiyalarla işləyənlər dərhal yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: n8n
FAQ2
What type of data is exposed by the CVE-2026-65589 vulnerability in n8n?
The vulnerability causes custom HTTP header credentials, such as API keys, in LLM sub-node execution data to remain unmasked, leaving them in plaintext within the execution records.
What action should users take to protect against CVE-2026-65589?
Users running n8n versions prior to 1.123.64 should update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.