CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:enterprise:node.js:*:*

History

No history.

Information

Published : 2026-08-11 13:19

Updated : 2026-08-28 18:32


NVD link : CVE-2026-72771

Mitre link : CVE-2026-72771

CVE.ORG link : CVE-2026-72771


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-863

Incorrect Authorization