0x324 - Teknik - N8ive by design -  one leaked key, three attack chains (leHACK)

0x324 - Teknik - N8ive by design - one leaked key, three attack chains (leHACK)

🎙 PolySécure Podcast 👥 539 📅 July 29, 2026 ⏱ 21 min 👁 8 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

n8nsecurityvulnerabilityJWTencryption keyLLMresponsible disclosure

Summary

In this special episode of PolySécure, the host interviews Guillaume Valadon, a researcher at GitGuardian, about his presentation at leHACK on the security of the n8n automation platform. Guillaume explains the genesis of the research, which stemmed from internal adoption of n8n at GitGuardian, an increase in n8n CVEs, and its inclusion in CISA’s KEV catalog. The research had three phases: first, detecting and validating n8n JWT tokens leaked on GitHub and Docker Hub, leading to 300 valid targets and responsible disclosure; second, exploring attack paths on up-to-date instances, including user enumeration, data table exfiltration, and secret leakage; third, exploiting outdated instances to dump SQLite databases and encryption keys. Guillaume discusses the challenges of securing n8n, which lacks built-in data validation, and recommends isolating it from the internet. He also highlights the use of LLMs like Claude to assist in vulnerability research, generating PoCs, and analyzing CVEs for variants. The episode concludes with Guillaume recommending n8n as an excellent training ground for AI-assisted vulnerability research.

165 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high, as it provides concrete insights into the security of a widely used automation platform. The argumentation is solid, based on hands-on research and real-world examples. Guillaume clearly explains the methodology and findings, and the discussion is well-structured. The use of LLMs in vulnerability research is a novel and interesting angle, adding practical value for security researchers.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is good, with references to CVE databases, KEV catalog, and responsible disclosure practices. However, the discussion lacks formal citations or links to specific sources. The title accurately reflects the content, focusing on a leaked key and attack chains. The content is based on expert opinion and original research, but not peer-reviewed. The public comments are not provided, so no analysis of public reception is possible.

146 words

Title / Content Match

The title accurately reflects the content: a technical discussion about n8n security, focusing on a leaked key and multiple attack chains, presented at leHACK.

Quality & Reliability

8/10

The content is an expert interview with a security researcher from GitGuardian, discussing a real-world security analysis of n8n. The claims are based on hands-on research, with references to CVE databases and responsible disclosure practices. The discussion is technical and grounded, though it lacks formal citations or peer-reviewed sources.

Key Moments

Cited Sources

  • CISA KEV Catalog — Mentioned as evidence of active exploitation of n8n vulnerabilities.
  • n8n CVE database — Referenced as the source of CVE information for n8n.
  • GitGuardian — The company where the researcher works, and the source of the research.

Concurring Sources

  • CISA KEV Catalog — Confirms active exploitation of n8n vulnerabilities.
  • n8n security advisories — Official security advisories for n8n.

Dissenting Sources

  • n8n's response to disclosures — The researcher mentioned that n8n did not always respond to vulnerability reports, indicating a potential lack of concern.

Contribution & Novelties

The episode provides a detailed case study of security research on n8n, highlighting the importance of responsible disclosure and the potential of LLMs in vulnerability discovery. It offers practical insights for securing n8n deployments and encourages further research in this area.

Pour aller plus loin :

78 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates a well-rounded and credible discussion, suitable for both security professionals and enthusiasts.

Reliability 8/10