SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65596

HIGH · CVSS 8.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

n8n versions prior to 1.123.64, 2.29.8, and 2.30.1 are vulnerable due to inadequate enforcement of "Allowed HTTP Request Domains" for HTTP-based credentials in the GraphQL node, allowing authenticated users to exfiltrate sensitive credentials by redirecting requests to an external server. This vulnerability poses a high risk, particularly for instances where credentials are configured to be accessible by non-owner users. Organizations utilizing n8n for workflow automation should prioritize immediate updates to mitigate potential credential leakage.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65596
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)