CVE-2026-65596

MEDIUM CVSS 4.0: 5.1 EPSS 0.21%
Updated Jul 27, 2026
N8N
Parameter Value
CVSS 5.1 (MEDIUM)
Affected Versions 2.0.0 — 2.29.8
Fixed In 1.123.64
Type CWE-863 (Incorrect Authorization)
Vendor N8N
Public PoC No

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 6

Configuration From (including) Up to (excluding)
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
1.123.64
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
1.123.64
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
2.0.0 2.29.8
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
2.0.0 2.29.8
N8n N8n
cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:community:node.js:*:*
N8n N8n
cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:enterprise:node.js:*:*