n8n published security advisories for multiple supported release branches after disclosure of several vulnerabilities, including a critical flaw tracked as CVE-2026-56348. The CVE affects versions before 2.20.0 and allows an authenticated user to abuse the POST /rest/dynamic-node-parameters/options endpoint to bypass Allowed HTTP Request Domains restrictions, causing the server to send credential-bearing HTTP requests to unauthorized hosts and potentially exfiltrate sensitive authentication data. The issue is remotely exploitable and impacts environments where users can access affected dynamic node functionality.
The broader advisory set also covers additional n8n weaknesses in releases prior to 2.28.1, 2.27.4, and 1.123.61, including another Allowed HTTP Request Domains bypass through the AI Agents MCP Connector, prototype pollution via workflow credentials that can lead to unauthenticated user and project enumeration, cross-issuer token exchange account binding caused by subject-only identity resolution, and a shared credential header leak through HTTP request pagination expressions. The Canadian Centre for Cyber Security urged administrators to review the advisories, upgrade to the patched versions, restrict access to exposed endpoints where possible, and monitor for unauthorized outbound requests that could indicate credential leakage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On June 27, 2026, a public oss-sec disclosure reported that n8n's GET /rest/workflows/from-url endpoint still allowed authenticated SSRF in default configurations, affecting versions up to 2.19.x and later versions when N8N_SSRF_PROTECTION_ENABLED was unset. The researcher said the protection was opt-in and defaulted to false, recommended enabling the flag and applying egress filtering, and noted no CVE or GHSA had been issued.
On June 24, 2026, n8n published security advisories covering multiple vulnerabilities across supported version branches. The affected releases were versions prior to 2.28.1, prior to 2.27.4, and prior to 1.123.61, including issues involving domain restriction bypass, prototype pollution, token exchange account binding, and credential header leakage.
CVE-2026-56348 was published as a critical vulnerability affecting n8n before version 2.20.0. The flaw in the POST /rest/dynamic-node-parameters/options endpoint allows authenticated users to bypass Allowed HTTP Request Domains restrictions and potentially exfiltrate credentials to unauthorized hosts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.