SSRF Protection Bypass in n8n's SearXNG Agent Tool
CVE-2026-77085

6.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77085?

The n8n platform, specifically versions prior to 2.34.1 and 2.33.x before 2.33.4, contains a vulnerability in the SearXNG Agent tool that allows an authenticated user to bypass the server-side request forgery (SSRF) protection. This occurs when an authorized user creates SearXNG credentials and configures a personal agent with a user-supplied API URL, which can point to internal network addresses. As a result, the n8n server may inadvertently connect to sensitive internal hosts and expose their response content to the external Agent chat output, posing significant security risks.

Affected Version(s)

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

n8n 2.34.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.