PatchSiren cyber security CVE debrief
CVE-2026-65596 n8n-io CVE debrief
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the 'Allowed HTTP Request Domains' restriction on HTTP-based credentials in the GraphQL node, allowing an authenticated user to exfiltrate restricted credentials by pointing the node's endpoint at a server they control. This vulnerability affects instances with configured 'Allowed HTTP Request Domains' for credentials and non-owner user access. The vulnerability has a medium severity and requires specific configurations to be exploited.
- Vendor
- n8n-io
- Product
- n8n
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of n8n versions before 1.123.64, 2.29.8, and 2.30.1 who have configured 'Allowed HTTP Request Domains' for credentials and allow non-owner users to access them. Additionally, operators, platform administrators, vulnerability management teams, and security teams may need to review and address this vulnerability to prevent potential credential exfiltration.
Technical summary
The n8n workflow automation tool contains a vulnerability in its GraphQL node. Specifically, the 'Allowed HTTP Request Domains' restriction is not enforced for HTTP-based credentials, such as Header Auth, Basic Auth, Query Auth, and OAuth. This oversight allows an authenticated user with the ability to create or edit workflows to exfiltrate restricted credentials by pointing the node's endpoint at a server they control. The affected configurations include instances where a credential has 'Allowed HTTP Request Domains' set and is usable by non-owner users.
Defensive priority
Medium priority due to the requirement for authenticated access and specific configuration.
Recommended defensive actions
- Update n8n to version 1.123.64, 2.29.8, or 2.30.1, or later.
- Review and restrict 'Allowed HTTP Request Domains' for credentials.
- Limit workflow creation and editing to trusted users.
- Monitor for suspicious workflow changes and credential usage.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-22T12:18:19.790Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The CVE record and NVD entry provide official details, but additional analysis may be required to fully understand the vulnerability.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T12:18:19.790Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.