Description
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Allows authenticated users to cause requests to arbitrary external origins via injected credential verification URLs
Action: Patch
AI Analysis

Impact

The vulnerability exists in n8n’s Instance AI credential setup flow, which accepts a credential test or verification URL without validating that it matches the workflow node’s origin. When a user injects attacker‑controlled fetched content into the setup process, the resulting URL can point to any external site. This causes authenticated requests, redirects or probes to reach that arbitrary origin, potentially exposing credentials or allowing the attacker to gather sensitive data or execute unauthorized actions on behalf of the user.

Affected Systems

The flaw affects the open source workflow automation platform n8n from n8n-io. Versions prior to 2.37.7 and 2.38.2 are vulnerable. Users running these releases are at risk until they upgrade to a patched version.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. An attacker must first gain a legitimate authenticated session and inject malicious content into the credential setup process. Once injected, the attacker can manipulate the service to send requests to any chosen third‑party origin, potentially exfiltrating data or performing unauthorized actions. The risk is moderate, driven by the need for user interaction and limited to authenticated accounts.

Generated by OpenCVE AI on September 8, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to version 2.37.7 or later 2.38.2, which includes the fix for the unvalidated probe URL issue.
  • Enable instance‑level validation in the Instance AI credential setup to reject any verification URLs that do not match the origin of the associated workflow node.
  • If an upgrade is not immediately possible, disable the Instance AI credential verification feature or configure the system to reject all external credential test URLs until a patch can be applied.

Generated by OpenCVE AI on September 8, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q5wm-mgqx-fv2f n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}


Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
Vendors & Products N8n
N8n n8n

Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.
Title n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T16:04:32.580Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86074

cve-icon Vulnrichment

Updated: 2026-09-09T15:50:00.548Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:14.273

Modified: 2026-09-11T18:20:24.770

Link: CVE-2026-86074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:15:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)