Allowed-Domains Bypass in n8n by n8n.io
CVE-2026-77081

5.1MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77081?

The n8n platform has a vulnerability where an allowed-domains bypass occurs within the GraphQL node. In cases where the Authentication parameter is set to expression mode, credentials associated with different types can be mismanaged. This flaw allows an authenticated user with the correct privileges to potentially exfiltrate domain-restricted credentials to an endpoint controlled by an attacker, thereby compromising the permissions associated with the leaked credential.

Affected Version(s)

n8n 0 < 1.123.69

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.