Логотип exploitDog
bind:CVE-2026-25631
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-25631

Количество 2

Количество 2

nvd логотип

CVE-2026-25631

2 дня назад

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentially leading to credential exfiltration. This only might affect user who have credentials that use wildcard domain patterns (e.g., *.example.com) in the "Allowed domains" setting. This issue is fixed in version 1.121.0 and later.

EPSS: Низкий
github логотип

GHSA-2xcx-75h9-vr9h

4 дня назад

n8n's domain allowlist bypass enables credential exfiltration

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentially leading to credential exfiltration. This only might affect user who have credentials that use wildcard domain patterns (e.g., *.example.com) in the "Allowed domains" setting. This issue is fixed in version 1.121.0 and later.

0%
Низкий
2 дня назад
github логотип
GHSA-2xcx-75h9-vr9h

n8n's domain allowlist bypass enables credential exfiltration

0%
Низкий
4 дня назад

Уязвимостей на страницу