Improper access control in n8n - #VU139111
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in multiple AI and LLM nodes when processing user-supplied base or endpoint URLs. A remote user can point a node to an attacker-controlled host to disclose sensitive information.
Only instances where a credential has "Allowed HTTP Request Domains" configured and is shared with non-owner users are vulnerable.