Medium severity5.4NVD Advisory· Published Jul 22, 2026· Updated Jul 27, 2026
CVE-2026-65593
CVE-2026-65593
Description
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
n8nnpm | < 1.123.64 | 1.123.64 |
n8nnpm | >= 2.30.0, < 2.30.1 | 2.30.1 |
n8nnpm | >= 2.0.0-rc.0, < 2.29.8 | 2.29.8 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-9w78-79q7-r4fpghsaADVISORY
- github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fpnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-65593ghsaADVISORY
- www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parametersnvdThird Party AdvisoryWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
News mentions
0No linked articles in our index yet.