Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the searchModels path send the openAiApi credential there. The affected implementation is packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModels.ts, which omitted assertOpenAiCredentialAllowsUrl. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Leakage and Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The OpenAI Chat Model node in the n8n workflow automation platform prevented user-facing calls from violating the credential allowed-domain restriction, but left the model-search dropdown endpoint unguarded. When a workflow editor sets the options.baseURL parameter to an arbitrary host, a request to the searchModels path is issued with the user’s stored OpenAI credential. The missing assertion that verifies the credential’s allowed domains caused the credential to be sent to the attacker‑controlled host. This creates a potential for exposing sensitive API keys to an unintended destination, effectively bypassing the intended domain restriction and allowing an attacker to gain unauthorized access to external services tied to those credentials.

Affected Systems

The vulnerability affects the open‑source n8n workflow automation platform, specifically any installation using version 1.123.75 or earlier, or version 2.37.6 or earlier, or version 2.38.1 or earlier. The issue is fixed starting with n8n releases 1.123.76, 2.37.7, and 2.38.2.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact and the common weakness classification suggests that the flaw allows a user with access to the workflow editor to influence outbound credentials. Exploitation requires the attacker to be able to modify workflow configurations or inject custom options.baseURL values, which may be feasible in environments where n8n is exposed to internal users or less‑privileged administrative accounts. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalogue, so while the risk is real, the probability of exploitation at the time of analysis is unclear.

Generated by OpenCVE AI on September 9, 2026 at 08:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update n8n to a fixed release (1.123.76, 2.37.7, or 2.38.2).
  • Alter network controls to block outbound traffic from n8n instances to arbitrary third‑party hosts, restricting connections only to the allowed OpenAI domain.
  • Limit administrative privileges for workflow editing to trusted users and enforce input validation on the baseURL parameter to restrict it to approved hosts.

Generated by OpenCVE AI on September 9, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-34ff-336r-5q23 n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the searchModels path send the openAiApi credential there. The affected implementation is packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModels.ts, which omitted assertOpenAiCredentialAllowsUrl. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T12:03:25.112Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86082

cve-icon Vulnrichment

Updated: 2026-09-14T12:03:20.268Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:17.240

Modified: 2026-09-14T13:18:57.487

Link: CVE-2026-86082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)