Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-72771

Опубликовано: 11 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
Версия до 2.31.5 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
Версия до 2.31.5 (исключая)
cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:enterprise:node.js:*:*

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
github
около 1 месяца назад

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863