CVE-2026-59209
n8n-io n8n
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination expression and exfiltrate the secret through item data. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.
- CVSS
- 7.1
- EPSS
- 0.29% 21.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10