CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3889

As cited

Copy frozen at (site build).

threat intel

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers discovered 321 n8n workflow automation instances that were exposed through leaked API tokens posted in public GitHub commits. The researchers demonstrated four attack methods attackers could use to access sensitive data and steal downstream credentials using these tokens without requiring a software vulnerability.

Why it matters: Organizations using n8n should audit GitHub and other public repositories for exposed API tokens and rotate credentials immediately, as attackers can leverage them to access workflows, integrations, and connected system credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers discovered that 321 live n8n instances were accepting application programming interface (API) tokens that had been leaked in public GitHub commits. The scan uncovered 4,576 distinct credentials linked to 1,255 hostnames, and the team showed four methods attackers could use those tokens to retrieve sensitive data and downstream credentials without needing a software vulnerability.

Why it matters: Organizations that run n8n and have inadvertently exposed API tokens in public GitHub commits are at risk of credential theft and data access; they should immediately revoke any exposed tokens and scan repositories for leaked secrets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers discovered that 321 live n8n instances were accepting application programming interface (API) tokens that had been leaked in public GitHub commits. The scan uncovered 4,576 distinct credentials linked to 1,255 hostnames, and the team showed four methods attackers could use those tokens to retrieve sensitive data and downstream credentials without needing a software vulnerability.

Why it matters: Organizations that run n8n and have inadvertently exposed API tokens in public GitHub commits are at risk of credential theft and data access; they should immediately revoke any exposed tokens and scan repositories for leaked secrets.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary