INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
n8n API Tokens Leaked Exposing Live Instances to Credential Theft
| 2026-08-05 10:35 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On August 5, 2026, a cyber operation was conducted where GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits. The attackers demonstrated four techniques to access sensitive data and downstream credentials without exploiting a software vulnerability. This attack affected approximately 896 reachable instances of the platform, with leaked credentials providing authenticated access to around 36% or roughly 26% of all hostnames identified. The operation worked by utilizing documented REST API functionality and standard HTTP requests, requiring no CVE exploitation or specialized tooling. As of March 31, 2026, more than 58% of n8n instances were running a version affected by at least one known security advisory, with over 100,000 instances visible through Shodan.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-68613 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
pr•••••.env
n8•••••.cloud
n8•••••.cloud
os•••••.getenv
se•••••.json
se•••••.json
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-68613CVE-2025-68613
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
Incident Timeline
February 2025
Threat actors used leaked n8n API tokens to expose live instances to credential theft, demonstrating techniques ranging from passive enumeration to active credential exfiltration.
Click on any entity below to view its context and source!
infrastructure
N8N
In practice, n8n API keys behave differently from self-contained JWTs that can be validated using their signatures alone.
The key must also still exist in the n8n database.
Testing a candidate token requires one read-only request with the key passed through the
X-N8N-API-KEY
header:
curl -s
The instance URL is often committed beside the token
An n8n API key is useful only when an attacker can identify the instance that accepts it.
When users configure Claude Code to interact with n8n, they may place both the instance URL and API key directly inside an approved
curl
command.
What an authenticated n8n token exposes
An n8n API token provides access according to the permissions of the user who created it.
If a developer placed an API key or token directly in a node parameter rather than using n8n's credential store, the value may appear in plaintext.
However, as our controlled tests demonstrate, an attacker with permission to create and execute workflows may be able to reference a stored credential and make n8n use or transmit it.
We reproduced them in a controlled n8n deployment built specifically for the research.
Example n8n workflow
Technique 1: Enumerating the instance
GET /api/v1/users
returned four accounts: the instance owner, two active users, and one pending registration.
Because n8n persists every node's full output, the OpenAI response appears in plaintext.
The key trick is that the HTTP Request node can use a stored n8n credential as its authentication method while sending requests to any URL.
When the workflow fired, n8n attached the credential value as a Bearer token in the outgoing
Authorization
header.
Together, these techniques show how an attacker can progress from a leaked n8n token to broader credential and data exposure using legitimate platform functionality:
Enumerate users, workflows, and security configuration.
Cause n8n to transmit a stored credential to attacker-controlled infrastructure.
During the research, we found real n8n instances containing similarly exposed patterns.
GitGuardian also made several disclosures directly to n8n during the research.
n8n acknowledged the reports, said it was aware of the issues and planned to address them, and subsequently closed the reports.
Approximately 30% of the 321 affected instances were hosted on
n8n.cloud
or similar managed services.
GitGuardian Public Monitoring already identifies exposed n8n API tokens and notifies affected developers through the company's
Good Samaritan
disclosure program.
The findings also led GitGuardian to update its n8n API key detector and validity checks to improve detection accuracy.
Takeaways
A leaked n8n token is not an isolated credential exposure.
An attacker could then delete the workflow and its associated execution records, leaving defenders with limited evidence inside n8n itself.
Revoking the exposed n8n token is the first step, but it may not be the last.
The risk is defined not only by the n8n instance, but by every system connected to it.
financial
$1,200 $ bounty
One company operated a bug bounty program, acknowledged the report, paid a $1,200 bounty, and revoked the credential immediately.
April 2025
Threat actors exploited leaked n8n API tokens, which were generated without expiration dates or had no "exp" claim, to access live instances and potentially steal credentials.
Click on any entity below to view its context and source!
infrastructure
N8N
Our pipeline extracted the n8n hostname committed alongside each token, sent a read-only validation request to the associated instance, and recorded the response.
We ran the same process against n8n Model Context Protocol API keys found in the same commit set.
MCP tokens allow AI assistants to call n8n workflows through the Model Context Protocol, making them a newer exposure surface than the REST API.
Why leaked n8n tokens can remain valid
An n8n API key is a signed JSON Web Token with an
"aud": "public-api"
audience claim.
Older n8n API keys frequently contain no
exp
claim defining when they expire.
n8n introduced a 30-day default expiration in version
1.78.0
in February 2025, but many of the tokens found during the research had been generated without an expiration date.
infrastructure
1.78.0
n8n introduced a 30-day default expiration in version
1.78.0
in February 2025, but many of the tokens found during the research had been generated without an expiration date.
March 11, 2026
Threat actors obtained and exposed leaked n8n API tokens, which provided authenticated access to live instances, allowing for credential theft.
Click on any entity below to view its context and source!
infrastructure
N8N
An attacker does not necessarily need to exploit an n8n vulnerability if a valid credential already provides authenticated access to the instance.
For this research, we collected every n8n API token it had identified in public GitHub commits since April 2025.
2026/08/05
Threat actors used leaked n8n API tokens to access sensitive data and downstream credentials without exploiting a software vulnerability.
Click on any entity below to view its context and source!
infrastructure
N8N
Leaked n8n API Tokens Exposed Live Instances to Credential Theft.
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames.
The implications extend well beyond n8n.
A sufficiently privileged n8n token can expose workflow definitions and execution data, allow attackers to use stored credentials, and, in some configurations, enable them to extract the underlying credential values.
To measure the potential blast radius, we reproduced four practical attack techniques in a controlled n8n environment.
Why n8n is a high-value target
n8n is an open-source, low-code workflow automation platform with AI agent support and hundreds of built-in integrations.
The platform can be self-hosted or deployed through
n8n.cloud
, and its
open-source repository
has attracted nearly 200,000 GitHub stars.
An n8n instance runs workflows composed of nodes.
But n8n still needs to decrypt and use them whenever a workflow runs.
With more than 100,000 instances visible through
Shodan
and more than 50 security advisories published since January 2026, n8n has attracted the same attention as other high-value integration platforms.
A decoded token looks like this:
{
"sub": "efdf9cca-049a-46aa-afdc-172f0824f6cb",
"iss": "n8n",
"aud": "public-api",
"jti": "aac8a7a8-c8c4-4855-8e8b-2806e90b16e1",
"iat": 1781551662
}
The token records its issuance time in the
iat
c…
"%{http_code}" \
-H "X-N8N-API-KEY: <token>" \
GET /api/v1/workflows
returns workflow definitions available to the authenticated user.
Bash(curl -s " \
-H "X-N8N-API-KEY: eyJhREDACTEDegE")
The audit endpoint provides an attack map
n8n's audit endpoint can provide an authenticated user with a security report for the instance:
curl -H "X-N8N-API-KEY: $JWT" \
-d "{}" \
-H "Content-Type: application/json" \
The response may identi…
data_breach
4,576 unique credentials
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames.
infrastructure
1,255 hostnames
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames.
…1,255
Publicly reachable instances
896
Instances accepting a leaked token
321
The 321 confirmed instances represent approximately 36% of the 896 reachable instances and 26% of all 1,255 hostnames identified in the commits.
infrastructure
5,469 Unique hostnames
The scan produced:
Stage
Count
Unique API tokens
4,576
GitHub commits containing tokens
5,469
Unique hostnames extracted
1,255
Publicly reachable instances
896
Instances accepting a leaked token
32…
Tactical Metrics
Metrics
infrastructure
N8N
Affected Product
Click for context!
Leaked n8n API Tokens Exposed Live Instances to Credential Theft.
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames.
The implications extend well beyond n8n.
A sufficiently privileged n8n token can expose workflow definitions and execution data, allow attackers to use stored credentials, and, in some configurations, enable them to extract the underlying credential values.
To measure the potential blast radius, we reproduced four practical attack techniques in a controlled n8n environment.
Why n8n is a high-value target
n8n is an open-source, low-code workflow automation platform with AI agent support and hundreds of built-in integrations.
The platform can be self-hosted or deployed through
n8n.cloud
, and its
open-source repository
has attracted nearly 200,000 GitHub stars.
An n8n instance runs workflows composed of nodes.
But n8n still needs to decrypt and use them whenever a workflow runs.
With more than 100,000 instances visible through
Shodan
and more than 50 security advisories published since January 2026, n8n has attracted the same attention as other high-value integration platforms.
An attacker does not necessarily need to exploit an n8n vulnerability if a valid credential already provides authenticated access to the instance.
For this research, we collected every n8n API token it had identified in public GitHub commits since April 2025.
Our pipeline extracted the n8n hostname committed alongside each token, sent a read-only validation request to the associated instance, and recorded the response.
We ran the same process against n8n Model Context Protocol API keys found in the same commit set.
MCP tokens allow AI assistants to call n8n workflows through the Model Context Protocol, making them a newer exposure surface than the REST API.
Why leaked n8n tokens can remain valid
An n8n API key is a signed JSON Web Token with an
"aud": "public-api"
audience claim.
A decoded token looks like this:
{
"sub": "efdf9cca-049a-46aa-afdc-172f0824f6cb",
"iss": "n8n",
"aud": "public-api",
"jti": "aac8a7a8-c8c4-4855-8e8b-2806e90b16e1",
"iat": 1781551662
}
The token records its issuance time in the
iat
c…
Older n8n API keys frequently contain no
exp
claim defining when they expire.
n8n introduced a 30-day default expiration in version
1.78.0
in February 2025, but many of the tokens found during the research had been generated without an expiration date.
In practice, n8n API keys behave differently from self-contained JWTs that can be validated using their signatures alone.
The key must also still exist in the n8n database.
Testing a candidate token requires one read-only request with the key passed through the
X-N8N-API-KEY
header:
curl -s
"%{http_code}" \
-H "X-N8N-API-KEY: <token>" \
GET /api/v1/workflows
returns workflow definitions available to the authenticated user.
The instance URL is often committed beside the token
An n8n API key is useful only when an attacker can identify the instance that accepts it.
When users configure Claude Code to interact with n8n, they may place both the instance URL and API key directly inside an approved
curl
command.
Bash(curl -s " \
-H "X-N8N-API-KEY: eyJhREDACTEDegE")
What an authenticated n8n token exposes
An n8n API token provides access according to the permissions of the user who created it.
If a developer placed an API key or token directly in a node parameter rather than using n8n's credential store, the value may appear in plaintext.
However, as our controlled tests demonstrate, an attacker with permission to create and execute workflows may be able to reference a stored credential and make n8n use or transmit it.
The audit endpoint provides an attack map
n8n's audit endpoint can provide an authenticated user with a security report for the instance:
curl -H "X-N8N-API-KEY: $JWT" \
-d "{}" \
-H "Content-Type: application/json" \
The response may identi…
We reproduced them in a controlled n8n deployment built specifically for the research.
Example n8n workflow
Technique 1: Enumerating the instance
GET /api/v1/users
returned four accounts: the instance owner, two active users, and one pending registration.
Because n8n persists every node's full output, the OpenAI response appears in plaintext.
The key trick is that the HTTP Request node can use a stored n8n credential as its authentication method while sending requests to any URL.
When the workflow fired, n8n attached the credential value as a Bearer token in the outgoing
Authorization
header.
Together, these techniques show how an attacker can progress from a leaked n8n token to broader credential and data exposure using legitimate platform functionality:
Enumerate users, workflows, and security configuration.
Cause n8n to transmit a stored credential to attacker-controlled infrastructure.
During the research, we found real n8n instances containing similarly exposed patterns.
GitGuardian also made several disclosures directly to n8n during the research.
n8n acknowledged the reports, said it was aware of the issues and planned to address them, and subsequently closed the reports.
Approximately 30% of the 321 affected instances were hosted on
n8n.cloud
or similar managed services.
GitGuardian Public Monitoring already identifies exposed n8n API tokens and notifies affected developers through the company's
Good Samaritan
disclosure program.
The findings also led GitGuardian to update its n8n API key detector and validity checks to improve detection accuracy.
Takeaways
A leaked n8n token is not an isolated credential exposure.
An attacker could then delete the workflow and its associated execution records, leaving defenders with limited evidence inside n8n itself.
Revoking the exposed n8n token is the first step, but it may not be the last.
The risk is defined not only by the n8n instance, but by every system connected to it.
Metrics
data_breach
4,576
Unique Credentials
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames.
Metrics
infrastructure
1,255
Hostnames
We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames.
…1,255
Publicly reachable instances
896
Instances accepting a leaked token
321
The 321 confirmed instances represent approximately 36% of the 896 reachable instances and 26% of all 1,255 hostnames identified in the commits.
Metrics
infrastructure
1.78.0
Software Version
n8n introduced a 30-day default expiration in version
1.78.0
in February 2025, but many of the tokens found during the research had been generated without an expiration date.
Metrics
infrastructure
5,469
Unique Hostnames
The scan produced:
Stage
Count
Unique API tokens
4,576
GitHub commits containing tokens
5,469
Unique hostnames extracted
1,255
Publicly reachable instances
896
Instances accepting a leaked token
32…
Metrics
financial
1,200
$ Bounty
One company operated a bug bounty program, acknowledged the report, paid a $1,200 bounty, and revoked the credential immediately.
Intelligence Sources
The Hacker News
2026-08-05
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
The Hacker News
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:11
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
Credential Theft
entity
5x
timeline
Temporal Reference
March 31, 2026
date
5x
general metric
%
30
%
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
general metric
Instances
100,000
instances
2x
general metric
Entities
401
entities
2x
general metric
Technique
3
technique
Contextual Telemetry
Context Block
22 METRICS
target region
Target Country
United States
country
industry
Targeted Sector
Technology
sector
tactic
Cyber Operation Type
Exfiltration
tactic
infrastructure
Affected Product
N8N
software
general metric
N8N Instances
321
n8n instances
data breach
Unique Credentials
4,576
unique credentials
infrastructure
Hostnames
1,255
hostnames
general metric
Github Stars
200,000
github stars
general metric
Security Advisories
50
security advisories
vulnerability
Exploited CVE
CVE-2025-68613
cve
vulnerability
CVSS Score
10
score
general metric
Aac8A7A8
4,855
aac8a7a8
infrastructure
Software Version
1.78.0
version
general metric
Example Workflow Technique
1
example workflow technique
general metric
Github
4,576
github
infrastructure
Unique Hostnames
5,469
unique hostnames
general metric
Reachable Instances
1,255
reachable instances
general metric
Mcp Tokens
372
mcp tokens
general metric
Response
200
response
general metric
Seconds
10
seconds
general metric
Affected Instances
100
affected instances
financial
$ Bounty
1,200
$ bounty
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.