n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
MediumCVE-2026-86074 · Published Sep 10, 2026
## Impact Instance AI credential setup accepted a credential test/verification URL without checking it matched the workflow node's origin. Exfiltration required the user to actively inject an attacker-controlled URL into the setup flow. The patch derives the credential destination from the node's own URL and confines authenticated requests, redirects and probes to that origin. ## Patches The issue has been fixed in n8n versions 2.38.2 and 2.37.7. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Disable the Instance AI module by removing `instance-ai` from the `N8N_ENABLED_MODULES` environment variable if it is not required. - Restrict n8n instance access to fully trusted users only. - Rotate any third-party API credentials that were set up using the Instance AI credential-setup flow on affected versions. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| n8n npm | >= 2.38.0, < 2.38.2 | 2.38.2 |
| < 2.37.7 | 2.37.7 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2026-86074
More n8n advisories
All n8n| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution | Medium | 2.37.7+1 more |
| Sep 10 | n8n: path traversal | Medium | 1.123.76+2 more |
| Sep 10 | n8n: missing authorization | Medium | 2.37.7+1 more |
| Sep 10 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check | Medium | 1.123.76+2 more |
| Sep 10 | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions | Medium | 1.123.76+2 more |
| Sep 10 | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open | Medium | 1.123.76+2 more |