Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. n8n
  4. ›
  5. CVE-2026-59207

CVE-2026-59207: n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector

July 22, 2026

The AI Agents feature did not enforce the “Allowed HTTP Request Domains” restriction configured on credentials. As a result, a member-level user who had been granted use-only access to a shared credential could cause its secret to be sent to an external server they control, by pointing an MCP tool at an arbitrary URL and running the agent.

This issue only affects instances where the AI Agents module is enabled via N8N_ENABLED_MODULES=agents and at least one credential with domain restrictions has been shared with a member-level user.

References

  • github.com/advisories/GHSA-h44j-f5r5-ph73
  • github.com/n8n-io/n8n/releases/tag/n8n%402.27.4
  • github.com/n8n-io/n8n/releases/tag/n8n%402.28.1
  • github.com/n8n-io/n8n/security/advisories/GHSA-h44j-f5r5-ph73
  • nvd.nist.gov/vuln/detail/CVE-2026-59207

Code Behaviors & Features

Detect and mitigate CVE-2026-59207 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.27.4, all versions starting from 2.28.0 before 2.28.1

Fixed versions

  • 2.27.4
  • 2.28.1

Solution

Upgrade to versions 2.27.4, 2.28.1 or above.

Impact 8.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-693: Protection Mechanism Failure

Source file

npm/n8n/CVE-2026-59207.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:19:13 +0000.