Description
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is treated as active; if two credentials of different types are attached, the node enforces the allowed-domains policy of only the first credential while still attaching material from both. An authenticated user with workflow-authoring rights can thereby send a domain-restricted credential to an attacker-controlled endpoint, exfiltrating it with the leaked credential's permissions.
Published: 2026-08-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exfiltration
Action: Patch
AI Analysis

Impact

The vulnerability in n8n allows an allowed‑domains bypass within the GraphQL node. When the node’s Authentication parameter is set to expression mode, every authentication‑gated credential selector is regarded as active. If two different credential types are attached, the node applies the allowed‑domains policy of only the first credential while still attaching material from both. An authenticated user with workflow‑authoring rights can thus send a domain‑restricted credential to an attacker‑controlled endpoint, exfiltrating it with the permissions of the leaked credential.

Affected Systems

This issue affects n8n releases prior to 1.123.69 and prior to 2.33.4 for major version 2.x, as well as prior to 2.34.1 for minor version 2.x. The affected product is n8n from n8n‑io.

Risk and Exploitability

The CVSS score of 5.1 classifies the impact as moderate. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated user who possesses workflow‑authoring privileges. Based on the description, it is inferred that an attacker must first author a workflow; once the bypass is triggered, a credential can be exfiltrated to an external endpoint. Because the exploit demands specific user rights and no public exploits at the time of analysis, the overall risk is moderate, but an organization allowing extensive workflow‑authoring should consider it a high priority for patching.

Generated by OpenCVE AI on August 20, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.69 or newer
  • Upgrade n8n to version 2.33.4 or newer, or to 2.34.1 or newer if using the 2.x branch
  • If upgrading immediately is not possible, restrict workflow‑authoring privileges to trusted users only and avoid using the GraphQL node with expression‑mode authentication until the patch is applied

Generated by OpenCVE AI on August 20, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is treated as active; if two credentials of different types are attached, the node enforces the allowed-domains policy of only the first credential while still attaching material from both. An authenticated user with workflow-authoring rights can thereby send a domain-restricted credential to an attacker-controlled endpoint, exfiltrating it with the leaked credential's permissions.
Title n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node
First Time appeared N8n
N8n n8n
Weaknesses CWE-639
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-21T11:21:21.502Z

Reserved: 2026-08-20T10:55:09.093Z

Link: CVE-2026-77081

cve-icon Vulnrichment

Updated: 2026-08-20T13:41:32.505Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T12:16:39.590

Modified: 2026-09-01T19:47:02.363

Link: CVE-2026-77081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:01Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key