CVE-2026-65593: n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Endpoints in /rest/dynamic-node-parameters/ lacked authorization scopes, making it reachable by any authenticated user with no workflow creation or execution required.
By supplying an absolute URL in the routing configuration, a caller could override the node type’s declared baseURL, defeating the restriction meant to confine requests to the node’s own upstream service. With SSRF protection disabled by default (N8N_SSRF_PROTECTION_ENABLED=false), this let an authenticated user make the n8n server issue HTTP requests to arbitrary internal targets.
References
- github.com/advisories/GHSA-9w78-79q7-r4fp
- github.com/n8n-io/n8n/releases/tag/n8n@1.123.64
- github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
- github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
- github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fp
- nvd.nist.gov/vuln/detail/CVE-2026-65593
- www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parameters
Code Behaviors & Features
Detect and mitigate CVE-2026-65593 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →