CVE-2026-59207 Details
Description
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.
A vulnerability exists in the n8n workflow automation platform, specifically in versions prior to 2.27.4 and 2.28.1. The issue arises in the AI Agents feature, which failed to properly enforce the 'Allowed HTTP Request Domains' restriction on credentials. This oversight allowed a member-level user with use-only access to a shared credential to send its secret to an external server under their control. The vulnerability is exploitable when an MCP tool is directed at an arbitrary URL, and it only affects instances with the AI Agents module enabled and at least one credential with domain restrictions shared with a member-level user.
Users can upgrade to n8n versions 2.27.4 or 2.28.1 to address this vulnerability. If an immediate upgrade is not possible, administrators can disable the AI Agents module, restrict credential sharing to trusted users, and audit credentials with domain restrictions for unexpected sharing relationships.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4 | [email protected] | Release Notes |
| https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1 | [email protected] | Release Notes |
| https://github.com/n8n-io/n8n/security/advisories/GHSA-h44j-f5r5-ph73 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 2.27.4 2.28.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |