{"id":"CVE-2026-54304","aliases":["GHSA-rm2v-h48j-895m"],"url":"https://o3.security/vulnerability/CVE-2026-54304","summary":"n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host","details":"## Impact\nAn authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operation to target an attacker-controlled URL. The node attached the SecurityScorecard API token to the outbound request, causing the credential to be sent to the attacker-controlled host bypassing credential configured limitations and exfiltrating.\n\n## Patches\nThe issue has been fixed in n8n versions 1.123.55, 2.25.7, and 2.26.1. Users should upgrade to one of these versions or later to remediate the vulnerability.\n\n## Workarounds\nIf upgrading is not immediately possible, administrators should consider the following temporary mitigations:\n- Limit workflow creation and editing permissions to fully trusted users only.\n- Disable the SecurityScorecard node by adding `n8n-nodes-base.securityScorecard` to the `NODES_EXCLUDE` environment variable.\n\nThese workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.","published":"2026-06-23T15:48:44.518Z","modified":"2026-08-12T03:51:47.716888398Z","cvss":null,"epss":{"score":0.00382,"percentile":0.31272,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"1.123.55"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.26.1"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.25.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54304.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-rm2v-h48j-895m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54304"},{"type":"PACKAGE","url":"https://github.com/n8n-io/n8n"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.716888398Z"}}