Credential Verification Flaw in n8n Workflow Automation Platform
CVE-2026-86074
5.9MEDIUM
What is CVE-2026-86074?
The n8n workflow automation platform, an open-source tool, contains a vulnerability in the Instance AI credential setup flow. This flaw allows an attacker to inject a malicious URL that bypasses origin checks, potentially leading to unauthorized authenticated requests or redirects to unintended origins. This issue affects n8n versions prior to 2.37.7 and 2.38.2 and has been addressed in the newer releases.
Affected Version(s)
n8n < 2.37.7 < 2.37.7
n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2
