CVE-2026-65596 Details
Description
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected.
A vulnerability exists in n8n versions prior to 1.123.64, 2.29.8, and 2.30.1, where the GraphQL node does not properly enforce the 'Allowed HTTP Request Domains' restriction on HTTP-based credentials. This issue allows an authenticated user who can create or edit workflows to direct the node's endpoint to a server they control, potentially exfiltrating restricted credentials. The vulnerability affects only those instances where a credential has 'Allowed HTTP Request Domains' configured and is accessible to non-owner users.
Users are advised to upgrade to n8n versions 1.123.64, 2.29.8, or 2.30.1. If an immediate upgrade is not possible, consider restricting workflow creation and editing permissions to trusted users, limiting credential sharing to trusted users, and auditing credentials with domain restrictions for unexpected sharing relationships.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-gq66-9cw5-j5jm | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-credential-exfiltration-via-graphql-node | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.64 >= 2.0.0, < 2.29.8 2.30.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |