CVE-2026-86082Medium· 6.5▾ Sunlitn8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
6.5 → 7.1
medium → high
7.1 → 6.5
high → medium
6.5 → 7.1
medium → high
7.1 → 6.5
high → medium
6.5 → 7.1
medium → high
7.1 → 6.5
high → medium
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the searchModels path send the openAiApi credential there. The affected implementation is packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModels.ts, which omitted assertOpenAiCredentialAllowsUrl. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
n8n < 1.123.76n8n >= 2.0.0, < 2.37.7n8n >= 2.38.0, < 2.38.2Upgrade past the affected range:
n8n 2.38.2Affected packages:
n8n < 1.123.76n8n >= 2.38.0, < 2.38.2n8n >= 2.0.0, < 2.37.7Patched in:
n8n 1.123.76n8n 2.38.2n8n 2.37.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform
CVE-2026-86076High· 8.8n8n is an open source workflow automation platform
CVE-2026-86079Medium· 6.5n8n is an open source workflow automation platform
CVE-2026-86080Medium· 5.3n8n is an open source workflow automation platform