Description
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Published: 2026-08-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

n8n versions before 2.32.1 do not enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. An attacker who has low-privileged access to a workflow editor can instruct the system to send requests to a host they control, which allows the exported credential secrets to be sent to that host for reuse against underlying services. The vulnerability enables the exfiltration of credential secrets and can lead to unauthorized access to services operating under those credentials.

Affected Systems

All releases of n8n by n8n-io prior to version 2.32.1 are affected. Low-privileged workflow editors with use-only access to shared credentials can exploit the flaw if AI or LLM nodes are used with user-configured URLs.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity for this credential theft flaw, but the EPSS score is not available and the vulnerability is not listed in CISA KEV. According to the description, exploitation requires an attacker to possess a low-privileged editor account and the ability to configure AI and LLM nodes with arbitrary base or endpoint URLs. Once those conditions are met, the attacker can redirect requests to malicious endpoints and exfiltrate sensitive credential information, enabling further compromise of downstream services.

Generated by OpenCVE AI on August 11, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update n8n to version 2.32.1 or later
  • If an immediate upgrade is not possible, disable or remove AI and LLM nodes that accept user-supplied URLs
  • Restrict or remove use-only access for workflow editors that have permissions to edit AI/LLM nodes

Generated by OpenCVE AI on August 11, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:enterprise:node.js:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Title n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes
First Time appeared N8n
N8n n8n
Weaknesses CWE-863
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T19:49:43.891Z

Reserved: 2026-08-10T15:06:16.417Z

Link: CVE-2026-72771

cve-icon Vulnrichment

Updated: 2026-08-14T19:49:30.510Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T13:19:07.490

Modified: 2026-08-28T18:32:54.270

Link: CVE-2026-72771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:45:03Z

Weaknesses