n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
Medium9.1CVE-2026-56348 · Published May 19, 2026 · updated Jul 20, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| n8n npm | < 2.20.0 | 2.20.0 |
Details and references
## Impact The `POST /rest/dynamic-node-parameters/options` endpoint allowed any authenticated user to cause the n8n server to issue HTTP requests including credentials bypassing the intended restrictions on which hosts could be contacted for that credential (Allowed HTTP Request Domains). The user needed to be authenticated and have access to the credential. ## Patches The issue has been fixed in n8n version 2.20.0. Users should upgrade to this version or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n access to fully trusted users only. - Limit credential sharing to users who genuinely require access to those credentials. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2026-56348
More n8n advisories
All n8n| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 19 | n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions CVE-2026-56352Medium6.4fixed in 2.19.3 | Medium6.4 | 2.19.3 |
| May 14 | n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints CVE-2026-45732High8.1fixed in 1.123.43, 2.20.7, 2.21.1 | High8.1 | 1.123.43, 2.20.7, 2.21.1 |
| May 14 | n8n Has a Source Control Pull SQL Injection CVE-2026-44792High9.0fixed in 1.123.43, 2.20.7, 2.21.1 | High9.0 | 1.123.43, 2.20.7, 2.21.1 |
| May 14 | n8n Has an XML Node Prototype Pollution Patch Bypass CVE-2026-44791Critical9.9fixed in 1.123.43, 2.20.7, 2.22.1 | Critical9.9 | 1.123.43, 2.20.7, 2.22.1 |
| May 14 | n8n Has an Arbitrary File Read via Git Node CVE-2026-44790Critical8.8fixed in 1.123.43, 2.20.7, 2.22.1 | Critical8.8 | 1.123.43, 2.20.7, 2.22.1 |
| May 14 | n8n: HTTP Request Node Pagination Prototype Pollution to RCE CVE-2026-44789Critical9.9fixed in 1.123.43, 2.20.7, 2.22.1 | Critical9.9 | 1.123.43, 2.20.7, 2.22.1 |