Evidence · DiggingBeagle record
GHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check
n8n advisory for a high-severity authorization flaw in inline Agent node-tool introspection that could decrypt a caller-selected instance credential without verifying project ownership; patched in 2.39.6 and 2.40.1.
- Published
- Sep 16, 2026
- Source role
- vendor statement
Evidence record
n8n advisory for a high-severity authorization flaw in inline Agent node-tool introspection that could decrypt a caller-selected instance credential without verifying project ownership; patched in 2.39.6 and 2.40.1.
Claim-level citations (5)
- supportsn8n inline Agent tool introspection could decrypt another project's credential: The vulnerable schema-resolution and credential-decryption step occurred before the language model was consulted, so model output was not required to cross the credential-ownership boundary.
Impact section; statement that schema resolution occurs before the LLM is consulted
- supportsn8n inline Agent tool introspection could decrypt another project's credential: n8n lists versions 2.39.6 and 2.40.1 as patched for GHSA-9rhv-fhr8-7q5r.
Affected versions; Patched versions; Patches section
- supportsn8n inline Agent tool introspection could decrypt another project's credential: The cited GHSA and NVD records establish the authorization flaw and patched versions but do not report a confirmed exploitation-in-the-wild population or quantified victim impact.
Advisory impact and patch information
- supportsn8n inline Agent tool introspection could decrypt another project's credential: n8n reported that registering a node tool on an inline Agent resolved the tool's input schema before the language model was consulted and decrypted whatever credential ID the caller named without checking that the caller's project owned it; an ordinary member could therefore cause another instance credential's plaintext secret to be sent to a host of their choosing.
Impact section
- supportsn8n inline Agent tool introspection could decrypt another project's credential: The attack requires an authenticated member able to provide a target credential ID, but n8n's advisory states that credential IDs are not treated as secrets and can appear in workflow JSON, exports and editor URLs.
Impact section; discussion of credential IDs and where they appear
Cite this record
DiggingBeagle. “GHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check.” Published Sep 16, 2026. https://diggingbeagle.com/sources/ghsa-9rhv-fhr8-7q5r-inline-agent-node-tool-introspection-decrypts-any-instance-c/