PT-2026-78940 · N8N · N8N
CVE-2026-77085
·
Published
2026-08-20
·
Updated
2026-09-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.34.1
n8n versions 2.33.x prior to 2.33.4
Description
The SearXNG Agent tool contains a Server-Side Request Forgery (SSRF) protection bypass. This occurs because the tool utilizes a raw HTTP client to send requests to a user-supplied API URL, bypassing the centralized SSRF protection mechanism. On instances where
N8N SSRF PROTECTION ENABLED is set to true, an authenticated user with permissions to create SearXNG credentials and configure a personal agent can specify an internal host as the API URL. This allows the n8n server to connect to the internal host and return the response content via the Agent chat output.Recommendations
Update n8n to version 2.34.1 or later.
Update n8n versions 2.33.x to 2.33.4 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N