Join our Newsletter — 33% off our NHI Course

n8n form RCE and credential vault exposure: what teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: A zero-click, unauthenticated RCE in n8n lets anyone who reaches a public multi-step form execute shell commands, with over 50,000 exposed forms identified and affected versions spanning self-hosted and cloud deployments, according to Pillar Security. The breach shows that public workflow forms can turn a single submission into credential vault compromise, making trust boundaries and input rendering the real security fault line.

Editorial analysis by NHI Mgmt Group, based on content published by Pillar Security: “Zero Click Unauthenticated RCE in n8n: A Contact Form That Executes Shell Commands”.

Key questions

Q: What breaks when a public workflow form can re-evaluate user input?

A: A public workflow form stops being a data collection tool and becomes an execution surface.

Q: Why do public n8n forms create credential exposure risk for connected systems?

A: Because the workflow engine that renders the form often sits next to the secrets that authenticate the platform to other services.

Q: What are the signs that an expression engine is failing safely?

A: The safest sign is that user input can be rendered only once and never interpreted again.

Practitioner guidance

  • Harden public workflow endpoints Remove internet exposure from any form or workflow that renders user input back to the browser unless there is a compelling business case and a compensating control set.
  • Separate rendering from execution Block any second-pass expression evaluation in user-facing pages and review template logic for paths that can reinterpret submitted values as code.
  • Inventory stored secrets in workflow platforms Treat workflow automation platforms as credential repositories and map every connected account, token, API key, and certificate they can decrypt or invoke.

Bottom line: A public workflow form can become an execution boundary when user input is evaluated more than once.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Public workflow forms create identity-adjacent trust without identity controls: A form that accepts internet traffic but also reaches into a credential-bearing automation platform inherits privileged risk without the usual access governance. The article shows that the problem is not just input handling, but the assumption that public submission is separate from execution authority. Practitioners should treat any such form as a governed control point, not a convenience feature.

A few things that frame the scale:

  • 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope, according to AI Agents: The New Attack Surface report.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, and revealing access credentials.

A question worth separating out:

Q: Who is accountable when a workflow automation platform exposes stored credentials?

A: Accountability sits with both the platform owner and the team that approved external exposure of the workflow. If the system stores non-human credentials, then identity governance, secrets ownership, and application security all share responsibility for the control failure. This is especially true when public input can trigger server-side execution.

👉 Read our full editorial: Zero-click n8n RCE exposes why public forms break NHI trust



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Public workflow forms are an identity boundary, not a presentation layer: When a form can trigger execution inside the same platform that stores credentials, the form becomes part of the trust perimeter. That changes the governance question from input handling to execution authority. Practitioners should treat any public workflow renderer as a privileged identity surface, because it can bridge unauthenticated users to stored secrets.

A few things that frame the scale:

  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
  • 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: Should teams prioritize form exposure review or secret rotation first after a workflow RCE?

A: Review exposed forms first so you can cut off the entry path, then rotate secrets if the vulnerable workflow was reachable or if execution occurred. Containment matters before remediation because a public form bug can be a live attack path, while secret rotation limits the blast radius if compromise already happened.

👉 Read our full editorial: Zero-click n8n RCE exposes why public forms break NHI trust


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.