{"id":"CVE-2026-54304","aliases":["GHSA-rm2v-h48j-895m"],"url":"https://o3.security/vulnerability/CVE-2026-54304","summary":"n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host","details":"n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operation to target an attacker-controlled URL. The node attached the SecurityScorecard API token to the outbound request, causing the credential to be sent to the attacker-controlled host bypassing credential configured limitations and exfiltrating. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.1.","published":"2026-06-23T15:48:44.518Z","modified":"2026-08-07T11:31:13.459421175Z","cvss":null,"epss":{"score":0.00354,"percentile":0.28131,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"1.123.55"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.26.1"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.25.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54304.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-rm2v-h48j-895m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54304"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:13.459421175Z"}}