CVE-2026-72771: n8n
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Affected products
- n8n n8n: before 2.31.5 (fixed in 2.31.5); version 2.32.0 only
Published 2026-08-11. Last modified 2026-08-28.