GHSA-pq6c-vh67-xpm3: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Summary
A flaw in n8n (a workflow automation tool) allowed users with certain permissions to access and decrypt credentials (secret login information) that belonged to other projects without proper authorization checks. An attacker could use this to steal sensitive secrets and send them to a server they controlled.
Solution / Mitigation
The issue has been fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should: restrict n8n instance access to fully trusted users only; audit and revoke any custom global roles carrying Log Streaming scopes (eventBusDestination:create, eventBusDestination:test, etc.), limiting those scopes to fully trusted users only; and review existing Log Streaming event destinations for unexpected webhook URLs and remove any that are not recognized, then rotate any credentials that may have been referenced. Note that these workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Vulnerability Details
EPSS: 0.3%
Yes
September 10, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-pq6c-vh67-xpm3
First tracked: September 10, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 75%