What is CVE-2026-65596?
This vulnerability in n8n allows authenticated users to bypass the 'Allowed HTTP Request Domains' restriction for HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) via the GraphQL node. Unlike the HTTP Request node, the restriction is not enforced, enabling potential requests to restricted domains. Upgrading to versions 1.123.64, 2.29.8, or 2.30.1 is recommended.
Azərbaycanca: Bu boşluq n8n iş axını avtomatlaşdırma alətində aşkarlanıb. GraphQL node-u vasitəsilə HTTP əsaslı etimadnamələr (Header Auth, Basic Auth, Query Auth, OAuth) üçün 'Allowed HTTP Request Domains' məhdudiyyəti tətbiq edilmir. Bu, autentifikasiya olunmuş istifadəçiyə iş axını yaradaraq və ya redaktə edərək məhdudlaşdırılmış domenlərə sorğu göndərməyə imkan verir. n8n-i 1.123.64, 2.29.8 və ya 2.30.1 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Through which n8n feature is this vulnerability exploited?
The vulnerability is exploited through the GraphQL node in the n8n workflow automation tool. The `Allowed HTTP Request Domains` restriction for HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) is not enforced in this node.
Which versions should be upgraded to in order to remediate this vulnerability?
To remediate this vulnerability, it is recommended to upgrade n8n to versions 1.123.64, 2.29.8, or 2.30.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.