Description
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authority‑blindness flaw in the AI Agents feature of n8n allows a member‑level user with use‑only access to a shared credential to point an MCP connector at any arbitrary URL. Because the Allowed HTTP Request Domains restriction is not enforced, the credential’s secret can be sent to an attacker‑controlled external server. The compromised data is the credential secret, exposing an improper control of security‑relevant information.

Affected Systems

Vulnerable versions of the n8n open‑source workflow automation platform are those prior to 2.27.4 and 2.28.1. Deployments that enable the AI shared credentials with use‑only rights granted to member‑level users fall under the affected user model.

Risk and Exploitability

The CVSS score of 7.1 reflects high impact with a modest exploitation effort. An EPSS score of < 1% denotes a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not present in the CISA KEV catalog. Attackers would likely exploit the a malicious endpoint, thereby exfiltrating the credential secret without needing elevated privileges.

Generated by OpenCVE AI on July 26, 2026 at 15:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy n8n version 2.27.4 or later – the patch reinstates domain‑restriction enforcement for AI Agents MCP connectors.
  • Verify that the Allowed HTTP Request Domains restriction‑level users from possessing use‑only access to shared credentials that can be transmitted to external services, or consider disabling the AI Agents feature for accounts with such permissions.
  • Revise the role configuration to remove use‑only credential access from non‑admin users until the patch is applied.

Generated by OpenCVE AI on July 26, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h44j-f5r5-ph73 n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
History

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
Vendors & Products N8n
N8n n8n

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.
Title n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-09T15:51:27.024Z

Reserved: 2026-07-02T21:05:02.924Z

Link: CVE-2026-59207

cve-icon Vulnrichment

Updated: 2026-07-09T15:51:14.517Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:30:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure