CVE-2026-65589: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Custom HTTP headers configured in credentials for certain LLM sub-nodes (including OpenAI, Anthropic, and Lemonade) are masked in the n8n UI but are written in plaintext into execution data during workflow runs. Any authenticated user with access to the execution data for an affected workflow can read the header names and values, which typically contain API keys or other secrets.
Because execution data can be persisted to the database and exported, leaked values may remain accessible beyond the lifetime of a single execution.
This issue only affects instances where workflows use LLM sub-nodes with custom headers defined in their credentials.
References
- github.com/advisories/GHSA-89gh-3pgc-v5h2
- github.com/n8n-io/n8n/releases/tag/n8n@1.123.64
- github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
- github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
- github.com/n8n-io/n8n/security/advisories/GHSA-89gh-3pgc-v5h2
- nvd.nist.gov/vuln/detail/CVE-2026-65589
- www.vulncheck.com/advisories/n8n-before-credential-exposure-via-llm-node-execution-data
Code Behaviors & Features
Detect and mitigate CVE-2026-65589 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →