Description
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the flaw involves an absence of enforcement of the Allowed HTTP Request Domains restriction in the AI Agents feature of n8n. A member‑level user with use‑only access to a shared credential can direct an MCP connector at any arbitrary URL. Because the restriction is not applied, the credential’s secret can be delivered to an attacker‑controlled external server, exposing the credential secret and indicating an improper control of security‑relevant information.

Affected Systems

Vulnerable versions of n8n are those prior to 2.27.4 and 2.28.1. Deployments that enable the AI Agents feature with use‑only shared credentials granted to member‑level users fall under the affected user model.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact with a modest effort required for exploitation. An EPSS score of < 1% suggests a very low but non‑zero probability of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker could use an arbitrary external endpoint to receive the credential secret without needing elevated privileges.

Generated by OpenCVE AI on August 12, 2026 at 10:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy n8n version 2.27.4 or later – the patch reinstates domain‑restriction enforcement for AI Agents MCP connectors.
  • Ensure that users with use‑only access to shared credentials are constrained by the Allowed HTTP Request Domains restriction, or disable the AI Agents feature for those users until the patch is applied.
  • Revise role configuration to remove use‑only credential access from non‑admin users until the patch is applied.

Generated by OpenCVE AI on August 12, 2026 at 10:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h44j-f5r5-ph73 n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
History

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
Vendors & Products N8n
N8n n8n

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.
Title n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-09T15:51:27.024Z

Reserved: 2026-07-02T21:05:02.924Z

Link: CVE-2026-59207

cve-icon Vulnrichment

Updated: 2026-07-09T15:51:14.517Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T16:16:46.470

Modified: 2026-07-09T19:37:19.377

Link: CVE-2026-59207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T10:15:02Z

Weaknesses