Case · DiggingBeagle record

n8n inline Agent tool introspection could decrypt another project's credential

n8n disclosed an authorization defect in inline Agent node-tool schema introspection, not a malicious module. An authenticated ordinary member who could supply a credential ID could cause schema resolution to decrypt that credential before the language model was consulted because the project-ownership check used on the invocation path was missing at this earlier step. Credential IDs were not treated as secrets and could appear in workflow JSON, exports and editor URLs. Patched releases 2.39.6 and 2.40.1 close this path; the cited advisory and NVD record establish the vulnerable capability and remediation, not exploitation in the wild or a victim count.

Assessment profile

Assessment method
Setting
production
Exploitation
not established
Evidence
Grade B
Remediation
patch available
Basis and provenance

The vendor advisory and NVD record establish the authorization defect and patch status. The focal evidence does not establish exploitation in the wild, so exploit status is not established and impact is left unbanded.

Assessed Oct 5, 2026 using diggingbeagle.assessment/1.

Timeline

  1. Sep 16, 2026
    disclosure

    n8n disclosed the inline Agent credential-ownership bypass

    The vendor advisory documented the pre-model schema-introspection path and listed patched releases 2.39.6 and 2.40.1.

  2. Oct 1, 2026
    Event type unspecified

    NVD published CVE-2026-103246

    NVD mapped CVE-2026-103246 to the n8n advisory.

Claims & evidence

CLM-N8N-AGENT-CVENVD published CVE-2026-103246 on October 1, 2026 and links it to the n8n GHSA describing this authorization bypass.supported

Basis: reported finding

Link to claim
CLM-N8N-AGENT-AI-ROLE-LIMITThe vulnerable schema-resolution and credential-decryption step occurred before the language model was consulted, so model output was not required to cross the credential-ownership boundary.supported

Basis: reported finding

Link to claim
CLM-N8N-AGENT-CREDENTIAL-PATCHn8n lists versions 2.39.6 and 2.40.1 as patched for GHSA-9rhv-fhr8-7q5r.supported

Basis: reported finding

Link to claim
CLM-N8N-AGENT-OUTCOME-BOUNDARYThe cited GHSA and NVD records establish the authorization flaw and patched versions but do not report a confirmed exploitation-in-the-wild population or quantified victim impact.supported

Basis: inference

Link to claim
CLM-N8N-AGENT-CREDENTIAL-BOUNDARYn8n reported that registering a node tool on an inline Agent resolved the tool's input schema before the language model was consulted and decrypted whatever credential ID the caller named without checking that the caller's project owned it; an ordinary member could therefore cause another instance credential's plaintext secret to be sent to a host of their choosing.supported
CLM-N8N-AGENT-IDENTIFIER-PRECONDITIONThe attack requires an authenticated member able to provide a target credential ID, but n8n's advisory states that credential IDs are not treated as secrets and can appear in workflow JSON, exports and editor URLs.supported

Basis: reported finding

Link to claim

Sources and citation

Material revision history

  1. Oct 5, 2026 · Published version · first publication · revision 68

Cite this record

DiggingBeagle. “n8n inline Agent tool introspection could decrypt another project's credential.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Sep 16, 2026. https://diggingbeagle.com/cases/n8n-inline-agent-tool-introspection-could-decrypt-another-project-s-credential/

Citation guidance