CVE-2026-56348
n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data.
| CWE | CWE-918 |
| Vendor | n8n |
| Product | n8n |
| Published | Jun 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for n8n n8n
Be the first to know when new critical vulnerabilities affecting n8n n8n are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low
Affected Versions
n8n / n8n
0 < 2.20.0
References
Credits
๐ vnth4nhnt