What is CVE-2026-72771?
CVE-2026-72771 is a vulnerability in n8n versions before 2.32.1 where the Allowed HTTP Request Domains allowlist is not enforced in certain AI and LLM nodes. This allows low-privileged workflow editors with use-only access to shared credentials to redirect requests to attacker-controlled hosts. Upgrading to n8n version 2.32.1 or later is recommended.
Azərbaycanca: CVE-2026-72771, n8n-in 2.32.1-dən əvvəlki versiyalarında AI/LLM node-larında 'Allowed HTTP Request Domains' allowlist-in düzgün tətbiq edilməməsi zəifliyidir. Aşağı səlahiyyətli workflow editor-lar, paylaşılmış kredensiallara yalnız istifadə icazəsi olsa belə, sorğuları attacker-in idarə etdiyi host-lara yönləndirə bilər. n8n-i 2.32.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which n8n users are affected by CVE-2026-72771?
Low-privileged workflow editors using n8n versions before 2.32.1 who have use-only access to shared credentials in AI/LLM nodes are affected by this vulnerability.
How can I mitigate CVE-2026-72771?
You should upgrade n8n to version 2.32.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.