Evidence · DiggingBeagle record

GHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check

n8n advisory for a high-severity authorization flaw in inline Agent node-tool introspection that could decrypt a caller-selected instance credential without verifying project ownership; patched in 2.39.6 and 2.40.1.

Published
Sep 16, 2026
Source role
vendor statement

Evidence record

n8n advisory for a high-severity authorization flaw in inline Agent node-tool introspection that could decrypt a caller-selected instance credential without verifying project ownership; patched in 2.39.6 and 2.40.1.

Read the original source ↗

Claim-level citations (5)

Cite this record

DiggingBeagle. “GHSA-9rhv-fhr8-7q5r: Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check.” Published Sep 16, 2026. https://diggingbeagle.com/sources/ghsa-9rhv-fhr8-7q5r-inline-agent-node-tool-introspection-decrypts-any-instance-c/

Citation guidance