Allowed-Domains Bypass in n8n by n8n.io
CVE-2026-77081
5.1MEDIUM
What is CVE-2026-77081?
The n8n platform has a vulnerability where an allowed-domains bypass occurs within the GraphQL node. In cases where the Authentication parameter is set to expression mode, credentials associated with different types can be mismanaged. This flaw allows an authenticated user with the correct privileges to potentially exfiltrate domain-restricted credentials to an endpoint controlled by an attacker, thereby compromising the permissions associated with the leaked credential.
Affected Version(s)
n8n 0 < 1.123.69
n8n 2.34.0 < 2.34.1
n8n 2.0.0 < 2.33.4
