In brief: GitGuardian found 4,576 leaked n8n API tokens in public GitHub commits, 321 of which still granted active access to live instances – without exploiting any software vulnerability.
Security researchers at GitGuardian discovered 4,576 unique n8n API tokens in public GitHub commits, which could be mapped to 1,255 hostnames. 321 of the tested instances actually still accepted the leaked tokens – without exploiting any software vulnerability at all.
GitGuardian specifically scanned public GitHub commits for exposed API tokens belonging to the workflow automation platform n8n. In doing so, the researchers identified 4,576 unique credentials, which could be mapped to 1,255 distinct hostnames. Of the instances tested, 896 accepted connection attempts at all, and for 321 of those the leaked tokens actually still worked – meaning attackers would have gained immediate API access to live production systems.
The researchers demonstrated four different ways these tokens could be abused to obtain sensitive data and downstream credentials. Crucially, none of these attack paths required a classic software vulnerability in the sense of a CVE. Access was achieved solely through n8n’s legitimate API functionality, combined with tokens accidentally checked in as plaintext or within configuration files.
For CISOs, this case shifts the focus away from classic patch management toward securing secrets throughout the entire development and automation lifecycle. n8n instances are frequently used to orchestrate workflows that themselves have access to databases, SaaS services, or internal APIs. A compromised API token from such a platform can therefore serve as a stepping stone to further systems, without an attacker ever needing to find or exploit a vulnerability in the n8n code itself.
In practice, this means secret scanning in repositories – including private repositories and commit histories – should be systematically extended to cover API tokens from automation platforms, not just classic cloud credentials. Additionally, regular rotation of n8n API tokens, restricting token permissions according to the principle of least privilege, and monitoring for unusual API access patterns on n8n instances are recommended, since a leak can otherwise go unnoticed for a long time without accompanying detection measures.
Source: thehackernews.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.