Case · DiggingBeagle record
n8n inline Agent tool introspection could decrypt another project's credential
n8n disclosed an authorization defect in inline Agent node-tool schema introspection, not a malicious module. An authenticated ordinary member who could supply a credential ID could cause schema resolution to decrypt that credential before the language model was consulted because the project-ownership check used on the invocation path was missing at this earlier step. Credential IDs were not treated as secrets and could appear in workflow JSON, exports and editor URLs. Patched releases 2.39.6 and 2.40.1 close this path; the cited advisory and NVD record establish the vulnerable capability and remediation, not exploitation in the wild or a victim count.
Assessment profile
Assessment method- Setting
- production
- Exploitation
- not established
- Evidence
- Grade B
- Remediation
- patch available
Basis and provenance
The vendor advisory and NVD record establish the authorization defect and patch status. The focal evidence does not establish exploitation in the wild, so exploit status is not established and impact is left unbanded.
Assessed Oct 5, 2026 using diggingbeagle.assessment/1.
Evidence basis: CLM-N8N-AGENT-CREDENTIAL-BOUNDARY · CLM-N8N-AGENT-CREDENTIAL-PATCH · CLM-N8N-AGENT-AI-ROLE-LIMIT · GHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check · NVD: CVE-2026-103246
Timeline
- Sep 16, 2026disclosure
n8n disclosed the inline Agent credential-ownership bypass
The vendor advisory documented the pre-model schema-introspection path and listed patched releases 2.39.6 and 2.40.1.
- Oct 1, 2026Event type unspecified
NVD published CVE-2026-103246
NVD mapped CVE-2026-103246 to the n8n advisory.
Claims & evidence
CLM-N8N-AGENT-CVENVD published CVE-2026-103246 on October 1, 2026 and links it to the n8n GHSA describing this authorization bypass.supported
Basis: reported finding
- supportsNVD: CVE-2026-103246government record
Quick Info; References; Affected Products
CLM-N8N-AGENT-AI-ROLE-LIMITThe vulnerable schema-resolution and credential-decryption step occurred before the language model was consulted, so model output was not required to cross the credential-ownership boundary.supported
Basis: reported finding
- supportsGHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Checkvendor statement
Impact section; statement that schema resolution occurs before the LLM is consulted
CLM-N8N-AGENT-CREDENTIAL-PATCHn8n lists versions 2.39.6 and 2.40.1 as patched for GHSA-9rhv-fhr8-7q5r.supported
Basis: reported finding
- supportsGHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Checkvendor statement
Affected versions; Patched versions; Patches section
CLM-N8N-AGENT-OUTCOME-BOUNDARYThe cited GHSA and NVD records establish the authorization flaw and patched versions but do not report a confirmed exploitation-in-the-wild population or quantified victim impact.supported
Basis: inference
- supportsGHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Checkvendor statement
Advisory impact and patch information
- contextNVD: CVE-2026-103246government record
NVD record and references
CLM-N8N-AGENT-CREDENTIAL-BOUNDARYn8n reported that registering a node tool on an inline Agent resolved the tool's input schema before the language model was consulted and decrypted whatever credential ID the caller named without checking that the caller's project owned it; an ordinary member could therefore cause another instance credential's plaintext secret to be sent to a host of their choosing.supported
Basis: reported finding
- supportsGHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Checkvendor statement
Impact section
CLM-N8N-AGENT-IDENTIFIER-PRECONDITIONThe attack requires an authenticated member able to provide a target credential ID, but n8n's advisory states that credential IDs are not treated as secrets and can appear in workflow JSON, exports and editor URLs.supported
Basis: reported finding
- supportsGHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Checkvendor statement
Impact section; discussion of credential IDs and where they appear
Sources and citation
Material revision history
- Oct 5, 2026 · Published version · first publication · revision 68
Cite this record
DiggingBeagle. “n8n inline Agent tool introspection could decrypt another project's credential.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Sep 16, 2026. https://diggingbeagle.com/cases/n8n-inline-agent-tool-introspection-could-decrypt-another-project-s-credential/