Moderate severityNVD Advisory· Published Jul 22, 2026· Updated Jul 24, 2026
n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters
CVE-2026-65593
Description
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
n8nnpm | < 1.123.64 | 1.123.64 |
n8nnpm | >= 2.30.0, < 2.30.1 | 2.30.1 |
n8nnpm | >= 2.0.0-rc.0, < 2.29.8 | 2.29.8 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-9w78-79q7-r4fpghsaADVISORY
- github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fpghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-65593ghsaADVISORY
- www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parametersghsathird-party-advisoryWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
News mentions
0No linked articles in our index yet.