Credential Exfiltration in n8n by n8n-io
CVE-2026-65596

5.1MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-65596?

The n8n application prior to versions 1.123.64, 2.29.8, and 2.30.1 contains a vulnerability that allows authenticated users to bypass the 'Allowed HTTP Request Domains' restriction on HTTP-based credentials (such as Header Auth, Basic Auth, Query Auth, and OAuth) within the GraphQL node. This oversight enables malicious users with workflow creation or editing rights to direct the endpoint of the node to a server that they control, potentially exfiltrating sensitive credentials. The issue primarily affects instances where credentials have the 'Allowed HTTP Request Domains' setting configured for non-owner users.

Affected Version(s)

n8n 0 < 1.123.64

n8n 0 < 2.30.1

n8n 0 < 2.29.8

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

34selen
.