VYPR
Medium severityNVD Advisory· Published Sep 8, 2026

CVE-2026-86074

CVE-2026-86074

Description

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • N8n Io/N8nreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <2.37.7 and <2.38.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.