CVE-2026-65593

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:enterprise:node.js:*:*

History

27 Jul 2026, 19:12

Type Values Removed Values Added
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fp - () https://github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fp - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parameters - () https://www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parameters - Third Party Advisory
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:community:node.js:*:*
First Time N8n
N8n n8n
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

24 Jul 2026, 22:16

Type Values Removed Values Added
Summary (en) n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled. (en) n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.

22 Jul 2026, 12:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-22 12:18

Updated : 2026-07-27 19:12


NVD link : CVE-2026-65593

Mitre link : CVE-2026-65593

CVE.ORG link : CVE-2026-65593


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-918

Server-Side Request Forgery (SSRF)