A critical server-side request forgery flaw in the n8n workflow automation platform, tracked as CVE-2026-56348, allowed any authenticated user to bypass the product’s Allowed HTTP Request Domains restriction and coerce the server into sending stored credentials to attacker-controlled hosts. The issue affected all versions before 2.20.0 and stemmed from missing credential permission validation in the refineResourceIds() path behind the POST /rest/dynamic-node-parameters/options endpoint, enabling exposure of API keys, OAuth tokens, and passwords without confirming credential:read access.
n8n fixed the vulnerability by adding credential access checks through CredentialsFinderService and returning a ForbiddenError when validation fails, while no public proof-of-concept had been reported at disclosure. Separately, the Canadian Centre for Cyber Security issued an advisory urging organizations to review n8n’s latest vendor notices and apply updates affecting versions prior to 1.123.64, 2.29.8, and 2.30.1, underscoring continued patching requirements across multiple release branches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-08, n8n published security advisories covering vulnerabilities affecting versions prior to 1.123.64, prior to 2.30.1, and prior to 2.29.8. The Canadian Centre for Cyber Security urged users and administrators to review the vendor advisories and apply updates.
A critical SSRF vulnerability, CVE-2026-56348, was disclosed in n8n, with reporting noting that exploitation was straightforward for authenticated users and could expose API keys, OAuth tokens, and passwords. As of June 2026, no public proof-of-concept exploit had been reported.
n8n addressed CVE-2026-56348 in version 2.20.0 by adding credential access checks through CredentialsFinderService and returning a ForbiddenError when validation fails. The flaw affected all versions prior to 2.20.0 and allowed authenticated users to bypass Allowed HTTP Request Domains restrictions to exfiltrate stored credentials.
Active exploitation of CVE-2026-33017 began within about 20 hours of the March 2026 advisory, with attackers conducting scanning, reconnaissance, and credential theft. Reported stolen data included OpenAI and Anthropic API keys, AWS credentials, and database passwords.
A March 2026 advisory disclosed CVE-2026-33017 in IBM Langflow, affecting versions up to 1.8.1 via the public flow-sharing endpoint that could pass attacker-controlled data into Python exec() without authentication or sandboxing. The issue was fixed in Langflow 1.9.0, but later reporting noted version confusion because 1.9.0 through 1.9.3 remained vulnerable to a different RCE flaw.
Perry fixed CVE-2026-53776 in version 0.5.1166 after researchers found that expired bearer tokens could remain valid indefinitely because expiration checking was disabled in the JWT verification path. The flaw affected versions before 0.5.1166 and enabled reuse of previously issued tokens after expiration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcethreataft.com
Open sourcethreataft.com
Open sourcethreataft.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.