GitGuardian Identifies Credential Theft Risk in n8n API Tokens
GitGuardian researchers have discovered that 321 n8n instances were vulnerable to credential theft due to exposed API tokens found in public GitHub commits. These tokens allowed unauthorized access to sensitive data and downstream credentials without exploiting any software vulnerabilities. The research identified 4,576 unique credentials associated with 1,255 hostnames, with 321 instances accepting at least one leaked token. The n8n platform, used for workflow automation, can expose workflow definitions and execution data, posing a significant security risk. The study demonstrated four attack techniques using standard HTTP requests to access sensitive information, emphasizing the need for organizations to revoke exposed tokens and review their security measures.