n8n API 토큰이 유출되어 크리덴셜 도난이 가능하다는 경고.
GitGuardian의 연구에 따르면, 321개의 n8n 인스턴스에서 API 토큰이 공개된 GitHub 커밋에 노출되었다. 연구진은 공격자가 소프트웨어 취약점을 이용하지 않고도 민감한 데이터 및 다운스트림 크리덴셜에 접근할 수 있는 4가지 방법을 시연했다. 이로 인해 4,576개의 고유한 크리덴셜이 1,255개의 호스트네임과 연결된 것을 확인했다.
n8n API tokens were leaked, exposing instances to credential theft risks.
According to researchers from GitGuardian, 321 n8n instances had API tokens exposed in public GitHub commits. They demonstrated four methods that attackers could exploit to access sensitive data and downstream credentials without needing to exploit a software vulnerability. A total of 4,576 unique credentials associated with 1,255 hostnames were identified in the scan.