CVE-2026-85172Medium· 6.4▾ Sunlitn8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HT…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
— → 6.4
none → medium
n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client uses the url property when both are present, allowing attackers to bypass validation by supplying a safe uri alongside a malicious url to access internal addresses.
n8n < 2.33.4n8n = 2.34.0Upgrade past the affected range:
n8n 2.33.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86082Medium· 6.5n8n is an open source workflow automation platform
CVE-2026-86074High· 7.1n8n is an open source workflow automation platform
GHSA-vhf8-cg2h-cg3pMediumn8n: SSRF Protection Bypass via MCP Client Node
GHSA-2x35-3fw4-9jr4Highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-38fj-36m5-783cMediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access