CVE-2026-59207High▾ Twilightn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.4%
The AI Agents feature did not enforce the "Allowed HTTP Request Domains" restriction configured on credentials. As a result, a member-level user who had been granted use-only access to a shared credential could cause its secret to be sent to an external server they control, by pointing an MCP tool at an arbitrary URL and running the agent.
This issue only affects instances where the AI Agents module is enabled via N8N_ENABLED_MODULES=agents and at least one credential with domain restrictions has been shared with a member-level user.
The issue has been fixed in n8n version 2.28.1 and 2.27.4. Users should upgrade to this version or later to remediate the vulnerability.
If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
agents from the N8N_ENABLED_MODULES environment variable.These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
n8n >= 2.28.0, < 2.28.1n8n < 2.27.4Upgrade to a patched release:
n8n 2.28.1n8n 2.27.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59254Mediumn8n: External Secrets Accessible via Workflow Expressions Outside Credentials
CVE-2026-59209Highn8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-59206Highn8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
GHSA-jwm3-qcfw-c5ppMedium· 5.0n8n: Python Code Node AST Validator Bypass
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform