PT-2026-63354 · N8N · N8N

·

CVE-2026-65596

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64 n8n versions prior to 2.29.8 n8n versions prior to 2.30.1
Description The GraphQL node fails to enforce the Allowed HTTP Request Domains restriction on HTTP-based credentials, including Header Auth, Basic Auth, Query Auth, and OAuth. This differs from the behavior of the HTTP Request node. An authenticated user with permissions to create or edit workflows can redirect the node endpoint to a server under their control to exfiltrate restricted credentials. This issue specifically affects instances where a credential has Allowed HTTP Request Domains configured and is accessible to users who are not the owners of that credential.
Recommendations Update to version 1.123.64 or later. Update to version 2.29.8 or later. Update to version 2.30.1 or later. Restrict workflow creation and editing permissions to fully trusted users only. Restrict credential sharing to fully trusted users only. Audit credentials with domain restrictions for unexpected sharing relationships.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65596
GHSA-88C4-PCQM-3R9P
GHSA-GQ66-9CW5-J5JM

Affected Products

N8N