Skip to content

n8n Discloses Security Incident Tied to a Third-Party Metabase Vulnerability

n8n disclosed that a vulnerability in third-party tool Metabase let an intruder access 136 customer records, including 5 with hashed n8n Cloud passwords.

n8n blog header graphic showing a workflow diagram with a highlighted search icon
Credit: n8n

The workflow automation platform n8n disclosed a security incident in which an unauthorized third party exploited a vulnerability in Metabase, a third-party analytics tool n8n uses internally, to access customer data. The unauthorized activity took place on August 3, and n8n said it learned of the breach on August 6; Metabase has since patched the flaw that allowed it.

n8n's investigation with Metabase and its own security, legal, and data teams confirmed that the intruder accessed and queried data available through the company's Metabase environment, according to n8n's incident update. The review found 136 records containing names and email addresses exposed across n8n's full user base, spanning both self-hosted n8n and n8n Cloud customers. Five of those records also carried bcrypt-hashed passwords tied to n8n Cloud accounts; n8n said self-hosted passwords are never shared with n8n, so those installations carry no password exposure from this incident. Because the Metabase queries returned a variable, non-deterministic set of rows each time they ran, n8n said it cannot determine exactly which records were viewed.

n8n's review also surfaced a separate, previously fixed bug that had stored a small number of n8n Cloud passwords in plain text. n8n considers it unlikely those records were touched during this incident but contacted all 25 affected account holders as a precaution. n8n said it has rotated potentially compromised credentials, reviewed its internal audit logs, notified its Data Protection Officer (DPO), and alerted the Berlin Commissioner for Data Protection and Freedom of Information, the German regulator that enforces GDPR in Berlin, where n8n GmbH is headquartered. The episode is a reminder that a vulnerability in a third-party SaaS tool a platform uses internally, not a flaw in its own product, can still expose that platform's customer records.

n8n is asking anyone it contacted directly about the incident to reset their password immediately, and it says any n8n Cloud customer can reset a password as an extra precaution even without a direct notice from n8n.

Share this story

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.