SECURITYTHE HACKER NEWS
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers discovered 321 n8n instances with API tokens exposed in public GitHub commits, enabling attackers to access sensitive data and downstream credentials through four demonstrated methods without exploiting software vulnerabilities. Scans identified 4,576 unique credentials linked to 1,255 hostnames.