CVE-2026-59207: n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
The AI Agents feature did not enforce the “Allowed HTTP Request Domains” restriction configured on credentials. As a result, a member-level user who had been granted use-only access to a shared credential could cause its secret to be sent to an external server they control, by pointing an MCP tool at an arbitrary URL and running the agent.
This issue only affects instances where the AI Agents module is enabled via N8N_ENABLED_MODULES=agents and at least one credential with domain restrictions has been shared with a member-level user.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-59207 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →