PT-2026-51414 · N8N · N8N

·

CVE-2026-56348

·

Published

2026-05-19

·

Updated

2026-07-27

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.20.0
Description An issue in the "POST /rest/dynamic-node-parameters/options" endpoint allows authenticated users with credential access to bypass Allowed HTTP Request Domains restrictions. This enables an attacker to force the server to issue HTTP requests containing credentials to unauthorized hosts, leading to the exfiltration of sensitive authentication data.
Recommendations Update to version 2.20.0 or later. Restrict n8n access to fully trusted users only. Limit credential sharing to users who genuinely require access to those credentials.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56348
GHSA-3875-8GCX-7V46

Affected Products

N8N