HTTP Request Node Vulnerability in n8n Workflow Automation Platform
CVE-2026-25631
5.3MEDIUM
What is CVE-2026-25631?
The n8n workflow automation platform has a security issue in its HTTP Request node prior to version 1.121.0. This vulnerability allows an authenticated attacker to exploit domain credential validation, enabling requests with sensitive credentials to be sent to unintended domains. Users employing wildcard domain patterns in their 'Allowed domains' settings may be particularly vulnerable, leading to potential credential exfiltration. It is essential for users to upgrade to version 1.121.0 or later to mitigate this risk.
Affected Version(s)
n8n < 1.121.0
