PT-2026-63351 · N8N · N8N

·

CVE-2026-65593

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64
Description Authenticated attackers can perform server-side request forgery (SSRF) via the /rest/dynamic-node-parameters/ endpoints, which lack authorization scopes. By providing absolute URLs in the routing configuration, a user can override the baseURL restrictions of a node type. When the N8N SSRF PROTECTION ENABLED variable is set to false, the server can be forced to issue HTTP requests to arbitrary internal targets.
Recommendations Update to version 1.123.64 or later. Set N8N SSRF PROTECTION ENABLED=true to enable filtering for private IP ranges and cloud metadata endpoints. Restrict n8n instance access to fully trusted users only. Restrict network egress from the n8n host to limit reachable internal services.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65593
GHSA-38FJ-36M5-783C
GHSA-9W78-79Q7-R4FP

Affected Products

N8N