Improper access control in n8n - #VU146792
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the model-search endpoint of the OpenAI Chat Model node when processing requests with a user-supplied options.baseURL. A remote user can send a specially crafted request to disclose sensitive information.
The issue affects the model-search dropdown path, which could reach an arbitrary host with the credential attached despite an administrator-configured allowed-domains restriction.