CVE-2026-56348Disclosure(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-22: 1Mentions · 2026-06-24: 1Technical Details · 2026-06-22: 1Technical Details · 2026-06-24: 106-2206-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ThreatAft@ThreatAft
    Disclosure

    🔐 CRITICAL: CVE-2026-56348 — n8n Credential Exfiltration CVSS 9.1. SSRF allows authenticated users to bypass domain restrictions and exfiltrate credentials via /rest/dynamic-node-parameters/options. 🔗 https://threataft.com/articles/cve-2026-56348-n8n-credential-exfiltration-ssrf #CyberSecurity #ThreatIntel #infosec #n8n

    Post summary

    The post announces the discovery of a critical SSRF vulnerability (CVE-2026-56348) in n8n, providing CVSS score and technical details of how credentials can be exfiltrated via a specific endpoint, but it does not mention exploitation, PoC, or patches.

    0000065
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56348 Credential Exfiltration in n8n Before 2.20.0 via Dynamic Node Parameters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56348

    Post summary

    The post announces CVE-2026-56348, a credential exfiltration flaw in n8n versions prior to 2.20.0 that exploits dynamic node parameters, but it provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000114
    4.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n-node.js-

Explore more