Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gq66-9cw5-j5jm | n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected. | |
| Title | n8n before 1.123.64 Credential Exfiltration via GraphQL Node | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-22T13:03:54.789Z
Reserved: 2026-07-22T10:45:44.833Z
Link: CVE-2026-65596
Updated: 2026-07-22T13:03:48.659Z
Status : Analyzed
Published: 2026-07-22T12:18:19.790
Modified: 2026-07-27T19:15:28.190
Link: CVE-2026-65596
No data.
OpenCVE Enrichment
Updated: 2026-08-04T00:00:09Z
Github GHSA