Junglewise Threat Intelligence

CVE-2026-56348: n8n credential exfiltration in dynamic-node-parameters endpoint

CVE-2026-56348 · Severity: critical · CVSS 9.1 · Published 2026-06-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform used to orchestrate business processes and integrations across applications. This vulnerability allows authenticated users with access to credentials to bypass security restrictions designed to limit which external hosts the system can connect to. An attacker could trick the n8n server into sending credentials to unauthorized external systems, compromising sensitive authentication data and potentially providing a foothold for further attacks on connected systems and services.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) issue (CWE-918) in the POST /rest/dynamic-node-parameters/options endpoint. The root cause is insufficient validation of HTTP request destinations, allowing authenticated users to bypass the "Allowed HTTP Request Domains" restriction intended to control which hosts can be contacted using stored credentials. An attacker must be authenticated to the n8n instance and have access to a credential; they can then craft requests to make the server issue HTTP requests containing credentials to arbitrary hosts. This enables credential exfiltration to attacker-controlled infrastructure. The vulnerability was patched in n8n version 2.20.0. Temporary workarounds include restricting n8n access to fully trusted users and limiting credential sharing, though these do not fully remediate the risk.

Affected products

  • n8n n8n < 2.20.0

Timeline

  • 2026-05-19: disclosed: Advisory GHSA-3875-8gcx-7v46 published
  • 2026-05-13: patched: Fix released in n8n version 2.20.0

References

Related threats