VYPR
High severity7.7GHSA Advisory· Published Jun 23, 2026· Updated Jun 26, 2026

CVE-2026-54304

CVE-2026-54304

Description

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operation to target an attacker-controlled URL. The node attached the SecurityScorecard API token to the outbound request, causing the credential to be sent to the attacker-controlled host bypassing credential configured limitations and exfiltrating. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
n8nnpm
< 1.123.551.123.55
n8nnpm
>= 2.26.0, < 2.26.12.26.1
n8nnpm
>= 2.0.0-rc.0, < 2.25.72.25.7

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

1