Credential Exfiltration in n8n by n8n-io
CVE-2026-65596
5.1MEDIUM
What is CVE-2026-65596?
The n8n application prior to versions 1.123.64, 2.29.8, and 2.30.1 contains a vulnerability that allows authenticated users to bypass the 'Allowed HTTP Request Domains' restriction on HTTP-based credentials (such as Header Auth, Basic Auth, Query Auth, and OAuth) within the GraphQL node. This oversight enables malicious users with workflow creation or editing rights to direct the endpoint of the node to a server that they control, potentially exfiltrating sensitive credentials. The issue primarily affects instances where credentials have the 'Allowed HTTP Request Domains' setting configured for non-owner users.
Affected Version(s)
n8n 0 < 1.123.64
n8n 0 < 2.30.1
n8n 0 < 2.29.8
