CVE-2026-72771: n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.32.1Patch Credential Restriction Bypass via AI/LLM Nodes - Configuration
Ensure n8n enforces the Allowed HTTP Request Domains allowlist in the configured AI/LLM nodes when user-supplied base or endpoint URLs are used; upgrade to n8n 2.32.1 or later to fix the bypass in versions before 2.32.1.
n8n AI/LLM nodes (e.g., where user-supplied base/endpoint URLs are configured) Allowed HTTP Request Domains allowlist = enforced for user-supplied base/endpoint URLs