CVE-2025-68613
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).
CISA federal remediation date Mar 25 · date passed
Vulnerabilities & Exploits · Credential Theft
Leaked tokens matter here because they act like standing keys into live automation systems. Patching n8n does not close that door if the token still works, since it can open workflows and reach stored credentials without exploiting the product itself.
GitGuardian found 4,576 unique n8n tokens in public GitHub commits across 1,255 hostnames. In testing, 321 of 896 reachable instances accepted at least one leaked token, which let the researchers access workflow data and downstream secrets through normal API access. The issue reaches self-hosted n8n and n8n.cloud deployments, especially where teams store cloud, database, or SaaS credentials inside workflows.
The forward risk is persistence: leaked source control can remain a live entry point after any CVE is fixed. That makes token rotation and secret review part of containment, not just patch management.
1 source · Aug 5
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).
CISA federal remediation date Mar 25 · date passed
The Hacker News
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian found 321 n8n instances accepting leaked GitHub tokens that could expose workflows, data, and downstream credentials without a CVE.
originalPart of the PlainSec briefing for 2026-08-05
Every edition of this story: Leaked n8n Tokens Became Live Access Keys