What happened
n8n published GitHub Security Advisories GHSA-64xh-79j6-r5v8 and GHSA-vhf8-cg2h-cg3p, and NVD published CVE-2026-72771 (CVSS 7.1) and CVE-2026-72768 (CVSS 6.4), describing allowlist and SSRF-protection bypasses specific to n8n's AI/LLM and MCP Client nodes.
Why it matters
n8n is a widely deployed workflow-automation platform increasingly used to orchestrate AI/LLM and MCP-based agent workflows; bypassing the domain allowlist specifically in AI nodes lets a low-privileged workflow editor pivot shared LLM provider credentials to attacker infrastructure or reach internal network services via the MCP Client node.
Attack vector
Multiple AI and LLM nodes fail to enforce the platform's Allowed HTTP Request Domains allowlist when user-supplied base/endpoint URLs are configured, letting low-privileged workflow editors with use-only access to shared credentials redirect requests to attacker-controlled hosts and exfiltrate credentials or internal data. A related flaw (CVE-2026-72768) lets the MCP Client node bypass SSRF protections entirely, reaching internal/blocked hosts.
Affected systems
n8n < 2.32.1
Mitigation
Upgrade n8n to >= 2.32.1.