Credential Exfiltration Vulnerability in n8n by n8n Team
CVE-2026-56348

5.3MEDIUM

Key Information:

Vendor

N8n

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-56348?

A vulnerability exists in n8n versions prior to 2.20.0 that allows authenticated users to exploit the POST /rest/dynamic-node-parameters/options endpoint. This flaw permits users to bypass the Allowed HTTP Request Domains restrictions, enabling attackers with valid credentials to send unauthorized HTTP requests from the n8n server. This can lead to the exfiltration of sensitive authentication data to untrusted hosts, compromising the integrity of user accounts and sensitive information.

Affected Version(s)

n8n 0 < 2.20.0

n8n 2.20.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vnth4nhnt
.