EXPOSURE n8n
SEVERITY CRITICAL
PROBE GET :5678/rest/settings
Is your n8n exposed?
Unclaimed setup or open settings: a stranger can take ownership and read your credentials.
Scan a host you own → Fix card Census
Why it matters
If your n8n setup page or settings endpoint answers without a login, a stranger can claim the instance as owner or read its configuration — and n8n holds your API keys and workflow credentials. Gate 0 testing showed bots hunting for credential files on exposed n8n within about an hour of the port going online.
How common is it?
42,130 n8n instances are reachable in the Shodan index. Fingerprint match, not a verified zero-auth count · src: Shodan count · `http.favicon.hash:-831756631,-670975485` · 2026-08
Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.
Fix it
The full walkthrough lives on the fix card, kept current in one place: