CyberSecurity News
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
AI summary
Researchers at GitGuardian discovered that numerous n8n instances were exposed due to leaked API tokens in public GitHub commits. A total of 321 instances were found to be accepting these exposed tokens, which could be used by attackers to access sensitive data and credentials. The researchers identified 4,576 unique credentials associated with 1,255 hostnames, highlighting the scope of the issue. Attackers could potentially use these tokens in various ways to gain unauthorized access without needing to exploit a software vulnerability. The exposed tokens were found in public GitHub commits, putting the associated n8n instances at risk of credential theft.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

