What happened
Fixed in the n8n 2.39.6/2.40.1 patch releases: the inline agent node feature performs tool introspection without validating that the workflow operator owns the credential IDs being referenced, so crafted agent definitions can cause the server to decrypt and return arbitrary stored secrets to the caller/attacker.
Why it matters
n8n is where enterprise AI agents live: its credential store holds the API tokens and service accounts those agents act with. An IDOR that lets a low-privilege workflow author decrypt and ship those secrets out is a direct path from workspace access to wholesale agent-identity compromise.
Attack vector
A user able to define an inline agent node can reference arbitrary credential IDs during node-tool introspection without an ownership check; the platform then decrypts the referenced secrets and the crafted agent workflow can exfiltrate the decrypted plaintext to an attacker-controlled host (CVSS 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H — scope-change confidentiality breach).
Affected systems
n8n before 2.39.6 and 2.40.0 before 2.40.1
Mitigation
Upgrade to n8n 2.39.6 / 2.40.1 or later; advisory GHSA-9rhv-fhr8-7q5r