HIGH 8.3 NVD
CVE-2026-103246
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference a
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-9rhv-fhr8-7q5r
- https://www.vulncheck.com/advisories/n8n-before-2.39.6-and-2.40-x-before-2.40.1-credential
This high severity vulnerability with a CVSS score of 8.3 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.