CVE-2026-72771
Last modified
CVE-2026-72771 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services..
Description
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| n8n-io | n8n | < 2.32.1 |
| n8n-io | n8n | < 2.31.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72771?
How severe is CVE-2026-72771?
How do I fix CVE-2026-72771?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72765n8n before 2.31.5 and before 2.32.1 contain a sandbox escape…8.7
- CVE-2026-72766n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.…8.2
- CVE-2026-72767n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.…8.7
- CVE-2026-72768n8n versions before 2.32.1 contain a server-side request for…6.4
- CVE-2026-72769n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype…6.1
- CVE-2026-72770n8n versions before 1.123.67 contain a path traversal vulner…7.1
- CVE-2026-72772n8n before 2.32.1 (and before 2.31.5) is vulnerable to accou…8.9
- CVE-2026-72773n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-co…4.9
- CVE-2026-72774n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credentia…7.1
- CVE-2026-72775n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injec…5.8
- CVE-2026-72778Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0…8.8
- CVE-2026-72779Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.…8.7
Are you affected by CVE-2026-72771?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
