Vulnerability  ·  2026-08-13

n8n AI/LLM nodes bypass Allowed HTTP Request Domains allowlist, enabling SSRF and credential leakage

VulnerabilityHigh impactGlobalCVE-2026-72771
n8n published GitHub Security Advisories GHSA-64xh-79j6-r5v8 and GHSA-vhf8-cg2h-cg3p, and NVD published CVE-2026-72771 (CVSS 7.1) and CVE-2026-72768 (CVSS 6.4), describing allowlist and SSRF-protection bypasses specific to n8n's AI/LLM and MCP Client nodes.
n8n is a widely deployed workflow-automation platform increasingly used to orchestrate AI/LLM and MCP-based agent workflows; bypassing the domain allowlist specifically in AI nodes lets a low-privileged workflow editor pivot shared LLM provider credentials to attacker infrastructure or reach internal network services via the MCP Client node.
Multiple AI and LLM nodes fail to enforce the platform's Allowed HTTP Request Domains allowlist when user-supplied base/endpoint URLs are configured, letting low-privileged workflow editors with use-only access to shared credentials redirect requests to attacker-controlled hosts and exfiltrate credentials or internal data. A related flaw (CVE-2026-72768) lets the MCP Client node bypass SSRF protections entirely, reaching internal/blocked hosts.
n8n < 2.32.1
Upgrade n8n to >= 2.32.1.
n8n GitHub Security Advisory GHSA-64xh-79j6-r5v8
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →