hacker-news · Crawled Aug 5, 2026

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

2 IoCs 1 CVEs
Read original article ↗

AI Summary

GitGuardian researchers identified 321 exposed and still-valid n8n API tokens in public GitHub commits, enabling unauthorized access to sensitive automation workflows, execution data, and stored credentials. Attackers can exploit these tokens to enumerate users, read or exfiltrate data, use or extract stored credentials (e.g., OpenAI API keys), and map high-risk configurations via the audit endpoint—all without exploiting a software vulnerability. The tokens remain valid due to missing expiration dates and poor credential hygiene, with some instances hosted on managed services like n8n.cloud. Responsible disclosure efforts met limited success, highlighting ongoing exposure risks.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename .claude/settings.json Details →
Filename .claude/settings.local.json Details →

MITRE ATT&CK TTPs 26 techniques