Junglewise Threat Intelligence

n8n credential restriction bypass in AI and LLM nodes

Severity: high · CVSS 7.1 · Published 2026-07-22

Technologies: N8n-Io N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform. A security flaw in its AI and Large Language Model (LLM) components allows users with limited permissions to bypass security restrictions on shared credentials. An attacker could redirect sensitive authentication keys to a server they control, potentially gaining unauthorized access to third-party services like OpenAI or Anthropic.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in n8n's AI and LLM nodes. The 'Allowed HTTP Request Domains' allowlist, designed to restrict credential usage to specific hosts, is not enforced when a user provides a custom base or endpoint URL. A low-privileged user with 'use-only' access to a shared credential can configure a malicious workflow to send that credential's secret to an attacker-controlled endpoint. This bypasses the intended security boundary between credential owners and workflow editors. The issue is resolved in versions 2.31.5 and 2.32.1.

Affected products

  • n8n-io n8n < 2.31.5, >= 2.32.0 < 2.32.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: patched
  • 2026-07-22: advisory

References

Related threats