mediumVulnerability

GHSA-fmvg-vhqq-r2mj

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-89gh-3pgc-v5h2. This link is maintained to preserve external references. ## Original Description n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.

Properties

ghsa_id
GHSA-fmvg-vhqq-r2mj
severity
medium
summary
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
cve_id
GHSA-fmvg-vhqq-r2mj
is_ghsa_only
true
ghsa_published
2026-07-22T12:32:17Z
source_url
https://github.com/advisories/GHSA-fmvg-vhqq-r2mj
ghsa_updated
2026-07-22T22:53:48Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information into Log File

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-fmvg-vhqq-r2mj — Ninja Signal Threat Intelligence | Ninja Signal