{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/data-enumeration/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*","cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*","cpe:2.3:a:n8n:n8n:2.28.0:*:*:*:community:node.js:*:*","cpe:2.3:a:n8n:n8n:2.28.0:*:*:*:enterprise:node.js:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-59209"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (Vulnerable: \u003c 1.123.61)","n8n (Vulnerable: \u003e= 2.28.0, \u003c 2.28.1)","n8n (Vulnerable: \u003e= 2.0.0-rc.0, \u003c 2.27.4)"],"_cs_severities":["high"],"_cs_tags":["n8n","vulnerability","credential-access","data-exfiltration","application-security","prototype-pollution","authentication-bypass","data-enumeration"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity vulnerability, CVE-2026-59209, exists in the n8n workflow automation platform, allowing authenticated users with \u0026quot;use-only editor access\u0026quot; to leak sensitive credentials. This flaw occurs in instances where the \u003ccode\u003eN8N_EXPRESSION_ENGINE\u003c/code\u003e environment variable is set to \u003ccode\u003evm\u003c/code\u003e and shared workflows utilize HTTP Request nodes with \u003ccode\u003eHTTP Header Auth\u003c/code\u003e credentials and pagination enabled. Attackers can craft malicious expressions within the pagination settings of such nodes to access and extract the \u003ccode\u003eHTTP Header Auth\u003c/code\u003e secret from the \u003ccode\u003e$request.headers\u003c/code\u003e object. The extracted secret can then be embedded into item data and subsequently exfiltrated via another HTTP Request node, effectively bypassing credential domain restrictions. This vulnerability impacts n8n versions prior to 1.123.61, versions 2.28.0 through 2.28.1, and versions 2.0.0-rc.0 through 2.27.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated n8n user with \u0026quot;use-only editor access\u0026quot; gains access to a shared workflow.\u003c/li\u003e\n\u003cli\u003eThe n8n instance is configured with \u003ccode\u003eN8N_EXPRESSION_ENGINE=vm\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe shared workflow contains an HTTP Request node that uses \u003ccode\u003eHTTP Header Auth\u003c/code\u003e credentials and has pagination enabled.\u003c/li\u003e\n\u003cli\u003eThe malicious user identifies this configuration and crafts an arbitrary expression within the pagination settings.\u003c/li\u003e\n\u003cli\u003eThis crafted expression is evaluated and accesses the \u003ccode\u003e$request.headers\u003c/code\u003e object, which contains the sensitive \u003ccode\u003eHTTP Header Auth\u003c/code\u003e secret.\u003c/li\u003e\n\u003cli\u003eThe expression extracts the secret and copies it into the workflow's item data.\u003c/li\u003e\n\u003cli\u003eThe item data, now containing the credential secret, is sent to a subsequent HTTP Request node configured to exfiltrate data to an attacker-controlled external endpoint.\u003c/li\u003e\n\u003cli\u003eThe sensitive \u003ccode\u003eHTTP Header Auth\u003c/code\u003e credential is exfiltrated, bypassing n8n's credential domain restrictions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-59209 allows lower-privileged, authenticated users to gain unauthorized access to sensitive \u003ccode\u003eHTTP Header Auth\u003c/code\u003e credentials. This enables them to bypass intended credential domain restrictions, potentially leading to unauthorized access to external services or systems integrated with n8n. The vulnerability can facilitate data exfiltration if the compromised credentials provide access to sensitive data sources. This issue affects specific configurations of n8n and poses a significant risk to organizations using shared workflows with credential-populated headers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances immediately to remediate CVE-2026-59209. Affected versions are \u003ccode\u003e\u0026lt; 1.123.61\u003c/code\u003e, \u003ccode\u003e\u0026gt;= 2.28.0, \u0026lt; 2.28.1\u003c/code\u003e, and \u003ccode\u003e\u0026gt;= 2.0.0-rc.0, \u0026lt; 2.27.4\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRestrict workflow sharing to fully trusted users only to mitigate the risk of CVE-2026-59209.\u003c/li\u003e\n\u003cli\u003eAvoid sharing credentials with use-only access to untrusted users, especially on workflows that employ HTTP Request nodes with pagination enabled.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T22:00:04Z","date_published":"2026-07-22T21:56:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-credential-leak/","summary":"An authenticated n8n user with 'use-only editor access' can exploit CVE-2026-59209 in shared workflows when `N8N_EXPRESSION_ENGINE=vm` is enabled, allowing them to read sensitive HTTP Header Auth credentials from the `$request.headers` object within a paginated HTTP Request node's expression and exfiltrate them, bypassing credential domain restrictions.","title":"n8n Shared Credential Leakage via HTTP Request Pagination Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-credential-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Data-Enumeration","version":"https://jsonfeed.org/version/1.1"}