Executive brief
n8n is a workflow automation platform. A security flaw in its AI and Large Language Model (LLM) components allows users with limited permissions to bypass security restrictions on shared credentials. An attacker could redirect sensitive authentication keys to a server they control, potentially gaining unauthorized access to third-party services like OpenAI or Anthropic.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in n8n's AI and LLM nodes. The 'Allowed HTTP Request Domains' allowlist, designed to restrict credential usage to specific hosts, is not enforced when a user provides a custom base or endpoint URL. A low-privileged user with 'use-only' access to a shared credential can configure a malicious workflow to send that credential's secret to an attacker-controlled endpoint. This bypasses the intended security boundary between credential owners and workflow editors. The issue is resolved in versions 2.31.5 and 2.32.1.
Affected products
- n8n-io n8n < 2.31.5, >= 2.32.0 < 2.32.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: patched
- 2026-07-22: advisory
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-64xh-79j6-r5v8
- https://github.com/n8n-io/n8n/commit/f69dfc6dd2178a14ea1624d2e1d403c2e755042f
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.31.5
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.32.1
- https://api.github.com/repos/n8n-io/n8n/security-advisories/GHSA-64xh-79j6-r5v8