VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-72771

CVE-2026-72771: n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when

Published Aug 11, 2026 CVSS 7.1

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.

Affected AI Products

llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.