PT-2026-63351 · N8N · N8N
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.64
Description
Authenticated attackers can perform server-side request forgery (SSRF) via the
/rest/dynamic-node-parameters/ endpoints, which lack authorization scopes. By providing absolute URLs in the routing configuration, a user can override the baseURL restrictions of a node type. When the N8N SSRF PROTECTION ENABLED variable is set to false, the server can be forced to issue HTTP requests to arbitrary internal targets.Recommendations
Update to version 1.123.64 or later.
Set
N8N SSRF PROTECTION ENABLED=true to enable filtering for private IP ranges and cloud metadata endpoints.
Restrict n8n instance access to fully trusted users only.
Restrict network egress from the n8n host to limit reachable internal services.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N