8.1

CVE-2026-65596

n8n before 1.123.64 Credential Exfiltration via GraphQL Node

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
N8n ≫ N8n SwEdition community SwPlatform node.js Version < 1.123.64
N8n ≫ N8n SwEdition enterprise SwPlatform node.js Version < 1.123.64
N8n ≫ N8n SwEdition community SwPlatform node.js Version >= 2.0.0 < 2.29.8
N8n ≫ N8n SwEdition enterprise SwPlatform node.js Version >= 2.0.0 < 2.29.8
N8n ≫ N8n Version 2.30.0 SwEdition community SwPlatform node.js
N8n ≫ N8n Version 2.30.0 SwEdition enterprise SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.112
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
disclosure@vulncheck.com 5.1 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/n8n-io/n8n/security/advisories/GHSA-gq66-9cw5-j5jm
Vendor Advisory
Mitigation
https://www.vulncheck.com/advisories/n8n-before-credential-exfiltration-via-graphql-node
Third Party Advisory