6.3

CVE-2026-65593

n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
N8nN8n SwEditioncommunity SwPlatformnode.js Version < 1.123.64
N8nN8n SwEditionenterprise SwPlatformnode.js Version < 1.123.64
N8nN8n SwEditioncommunity SwPlatformnode.js Version >= 2.0.0 < 2.29.8
N8nN8n SwEditionenterprise SwPlatformnode.js Version >= 2.0.0 < 2.29.8
N8nN8n Version2.30.0 SwEditioncommunity SwPlatformnode.js
N8nN8n Version2.30.0 SwEditionenterprise SwPlatformnode.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
disclosure@vulncheck.com 6.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fp
Vendor Advisory
Mitigation
https://www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parameters
Third Party Advisory