n8n API Tokens Exposed on GitHub: 321 Instances Accepted Compromised Credentials

GitGuardian found 4,576 n8n API tokens on GitHub, with 321 instances using compromised credentials. Learn about the risks and how to secure your n8n workflows.

n8n API Tokens Exposed on GitHub: 321 Instances Accepted Compromised Credentials
Data Breaches

Illustrative image generated with AI

Authenticated Access Can Lead to Connected Systems

GitGuardian identified 4,576 n8n API tokens published across 5,469 GitHub commits, associated with 1,255 hostnames.

Of the 896 reachable instances, 321 accepted at least one compromised token. This represents 36% of accessible instances and approximately 26% of the identified hostnames.

Exploiting an n8n vulnerability is not required. A still-valid token and the documented REST APIs may be enough to gain authenticated access.

Workflows, Credentials, and Integrations Within the Attack Surface

n8n is a low-code workflow automation platform available both as a self-hosted deployment and through n8n.cloud. Its integrations can connect databases, repositories, cloud environments, AI services, and internal systems.

In a controlled environment, GitGuardian reproduced four attack techniques. An attacker could:

  • read workflows and execution data;
  • create or modify automations;
  • use credentials stored in workflows;
  • extract the corresponding values in certain configurations;
  • reach connected downstream systems.

Credentials are encrypted at rest using N8N_ENCRYPTION_KEY, but the instance must decrypt them during execution. Protecting this key is therefore essential.

The researchers also found 372 MCP tokens, 7 of which were still valid. These tokens can increase the risk when AI assistants invoke workflows or interact with the n8n environment.

Non-Expiring Tokens and Outdated Versions

Older tokens may not include the exp claim and can therefore remain valid indefinitely. n8n introduced a default 30-day expiration in version 1.78.0, released in February 2025, but the change does not automatically invalidate previously generated tokens.

The risk is compounded by exposed instances: more than 100,000 were visible through Shodan. In addition, over 50 security advisories had been published since January 2026; as of March 31, 2026, 58% of the analyzed instances were running versions affected by at least one advisory.

One of these is CVE-2025-68613, which has a CVSS score of 9.9 and was added to the KEV catalog on March 11, 2026. However, it is not required for the attack scenario based on valid tokens.

Immediate Revocation and Connected-System Review

Administrators should:

  1. revoke and regenerate exposed n8n and MCP tokens;
  2. search public and private repositories for tokens, hostnames, and credential references;
  3. update n8n to versions unaffected by the advisories;
  4. enforce short expiration periods and automatic rotation;
  5. limit Internet exposure and restrict API access;
  6. review workflows, execution logs, accounts, and downstream systems;
  7. protect N8N_ENCRYPTION_KEY and reduce the privileges of credentials used by workflows.

The presence of a token in a historical commit should be treated as a compromise, even if the file was later removed.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →