n8n npm Package Vulnerability: External Secrets Exposure Risk
An early warning has been issued regarding a vulnerability in the n8n npm package that reportedly allows authenticated users with project editor access to read the plaintext value of external secrets. This issue affects instances with the external secrets feature configured.
What happened
The n8n npm package had a vulnerability where external secrets were incorrectly resolved in workflow node expressions. This issue appears to allow authenticated users with project editor access to read the plaintext value of external secrets. The vulnerability affects instances with the external secrets feature configured.
To assess your exposure, check if your n8n instances are using versions prior to 2.27.4 or 2.28.1 and have the external secrets feature enabled. It is under investigation whether this vulnerability has been actively exploited.
The recommended action is to upgrade to n8n version 2.27.4 or 2.28.1 or later to remediate the vulnerability. For more detailed information, consult the primary sources.
How 0Day mitigates this
n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.