Skip to content
n8nGHSA-q5wm-mgqx-fv2f

n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

MediumCVE-2026-86074 · Published Sep 10, 2026

## Impact Instance AI credential setup accepted a credential test/verification URL without checking it matched the workflow node's origin. Exfiltration required the user to actively inject an attacker-controlled URL into the setup flow. The patch derives the credential destination from the node's own URL and confines authenticated requests, redirects and probes to that origin. ## Patches The issue has been fixed in n8n versions 2.38.2 and 2.37.7. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Disable the Instance AI module by removing `instance-ai` from the `N8N_ENABLED_MODULES` environment variable if it is not required. - Restrict n8n instance access to fully trusted users only. - Rotate any third-party API credentials that were set up using the Instance AI credential-setup flow on affected versions. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

GitHub advisory

Affected versions

PackageAffectedFixed in
n8n
npm
>= 2.38.0, < 2.38.22.38.2
< 2.37.72.37.7
Details and references

More n8n advisories

All n8n
Advisory
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
MediumSep 10
n8n: path traversal
MediumSep 10
n8n: missing authorization
MediumSep 10
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
MediumSep 10
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
MediumSep 10
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
MediumSep 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.