SSRF Protection Bypass in n8n's SearXNG Agent Tool
CVE-2026-77085
6.3MEDIUM
What is CVE-2026-77085?
The n8n platform, specifically versions prior to 2.34.1 and 2.33.x before 2.33.4, contains a vulnerability in the SearXNG Agent tool that allows an authenticated user to bypass the server-side request forgery (SSRF) protection. This occurs when an authorized user creates SearXNG credentials and configures a personal agent with a user-supplied API URL, which can point to internal network addresses. As a result, the n8n server may inadvertently connect to sensitive internal hosts and expose their response content to the external Agent chat output, posing significant security risks.
Affected Version(s)
n8n 2.34.0 < 2.34.1
n8n 2.0.0 < 2.33.4
n8n 2.34.1
