Vulnerability  ·  2026-10-02

n8n inline agent node-tool introspection fails to validate credential ownership — plaintext credential decryption and exfiltration

VulnerabilityHigh impactGlobalCVE-2026-103246
Fixed in the n8n 2.39.6/2.40.1 patch releases: the inline agent node feature performs tool introspection without validating that the workflow operator owns the credential IDs being referenced, so crafted agent definitions can cause the server to decrypt and return arbitrary stored secrets to the caller/attacker.
n8n is where enterprise AI agents live: its credential store holds the API tokens and service accounts those agents act with. An IDOR that lets a low-privilege workflow author decrypt and ship those secrets out is a direct path from workspace access to wholesale agent-identity compromise.
A user able to define an inline agent node can reference arbitrary credential IDs during node-tool introspection without an ownership check; the platform then decrypts the referenced secrets and the crafted agent workflow can exfiltrate the decrypted plaintext to an attacker-controlled host (CVSS 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H — scope-change confidentiality breach).
n8n before 2.39.6 and 2.40.0 before 2.40.1
Upgrade to n8n 2.39.6 / 2.40.1 or later; advisory GHSA-9rhv-fhr8-7q5r
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →