Interestana
Home/News/n8n API Tokens Leaked on GitHub, Exposing Live Instances
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

n8n API Tokens Leaked on GitHub, Exposing Live Instances

n8n API Tokens Leaked on GitHub, Exposing Live Instances

GitGuardian researchers have identified a significant security vulnerability affecting the workflow automation tool n8n, where API tokens were exposed in public GitHub commits, potentially leading to credential theft and unauthorized access to sensitive data. The research team discovered 321 live n8n instances that were accessible through these leaked API tokens. These tokens were found within public GitHub repositories, indicating a failure in developers' practices to keep sensitive credentials private.

In their investigation, GitGuardian scanned public GitHub commits and uncovered a total of 4,576 unique credentials linked to 1,255 hostnames. This extensive exposure highlights a broad risk across numerous n8n deployments. The researchers demonstrated four distinct methods through which malicious actors could exploit these exposed API tokens. These methods allowed attackers to gain access to sensitive information stored within the n8n instances and to subsequently steal downstream credentials that were managed or accessed by these instances. Crucially, these attacks did not rely on exploiting any pre-existing software vulnerabilities within the n8n platform itself, meaning that even up-to-date n8n installations were at risk if their API tokens were inadvertently committed to public repositories.

The implications of this discovery are substantial for businesses and individuals using n8n for their workflow automation. Exposed API tokens can grant attackers a direct gateway into systems, potentially leading to data breaches, financial fraud, and reputational damage. The ease with which these tokens were found in public code repositories suggests a widespread issue with developer awareness and secure coding practices. GitGuardian's findings underscore the critical importance of implementing robust security measures, such as using environment variables or secrets management tools, to protect API keys and other sensitive credentials from accidental exposure.

While the exact number of compromised instances and the extent of data loss are not fully detailed, the sheer volume of discovered credentials and hostnames points to a considerable security risk. The researchers' ability to demonstrate multiple attack vectors further emphasizes the severity of the situation. This incident serves as a stark reminder for developers and organizations to regularly audit their code repositories for exposed secrets and to enforce strict policies regarding the handling of sensitive information. The n8n team has been alerted to these findings, and it is expected that they will provide guidance or implement measures to mitigate such exposures in the future, though specific actions taken by n8n were not detailed in the initial report.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next