PT-2026-63354 · N8N · N8N
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.64
n8n versions prior to 2.29.8
n8n versions prior to 2.30.1
Description
The GraphQL node fails to enforce the Allowed HTTP Request Domains restriction on HTTP-based credentials, including Header Auth, Basic Auth, Query Auth, and OAuth. This differs from the behavior of the HTTP Request node. An authenticated user with permissions to create or edit workflows can redirect the node endpoint to a server under their control to exfiltrate restricted credentials. This issue specifically affects instances where a credential has Allowed HTTP Request Domains configured and is accessible to users who are not the owners of that credential.
Recommendations
Update to version 1.123.64 or later.
Update to version 2.29.8 or later.
Update to version 2.30.1 or later.
Restrict workflow creation and editing permissions to fully trusted users only.
Restrict credential sharing to fully trusted users only.
Audit credentials with domain restrictions for unexpected sharing relationships.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N