GHSA-38fj-36m5-783cMedium▾ SunlitDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-9w78-79q7-r4fp. This link is maintained to preserve external references.
n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
n8n < 1.123.64Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-86082Medium· 6.5n8n is an open source workflow automation platform
CVE-2026-86074High· 7.1n8n is an open source workflow automation platform
GHSA-vhf8-cg2h-cg3pMediumn8n: SSRF Protection Bypass via MCP Client Node
GHSA-2x35-3fw4-9jr4Highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
CVE-2026-85172Medium· 6.4n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes