CVE Tools
Back to feed
Incident n8n Automation Platform n8n

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

The Hacker News·By The Hacker News··13 min read
CVE Tools coverage

GitGuardian discovered 321 active n8n instances that accepted leaked API tokens from public GitHub commits. These tokens granted access to workflow definitions, execution logs, and stored credentials—without needing to exploit a software vulnerability. The affected versions of n8n Automation Platform were used in cloud and self-hosted setups, with some instances running known unpatched CVEs like CVE-2025-68613. Attackers could leverage these tokens to enumerate users, extract secrets, or even exfiltrate live credentials via crafted workflows. The findings highlight the risks of misconfigured automation platforms and underscore the importance of revoking exposed tokens and monitoring for credential leaks.