CVE-2026-65593

EUVD-2026-47637
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.91%
Affected Products (NVD)
VendorProductVersion
n8nn8n
𝑥
< 1.123.64
n8nn8n
𝑥
< 1.123.64
n8nn8n
2.0.0 ≤
𝑥
< 2.29.8
n8nn8n
2.0.0 ≤
𝑥
< 2.29.8
n8nn8n
2.30.0
n8nn8n
2.30.0
𝑥
= Vulnerable software versions