GHSA-6m32-557f-fqq9HighCVSS 7.1

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.

🔗 References (4)