{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3an8nn8n2.28.0node.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*","cpe:2.3:a:n8n:n8n:2.28.0:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-59207"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (\u003e= 2.28.0, \u003c 2.28.1)","n8n (\u003c 2.27.4)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","n8n","restriction-bypass","data-exfiltration","ai-agents"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eThe GHSA-h44j-f5r5-ph73 advisory details CVE-2026-59207, a restriction bypass vulnerability in the n8n automation platform's AI Agents module. Versions prior to 2.27.4 and versions 2.28.0 up to, but not including, 2.28.1 are affected. This flaw allows an authenticated member-level user, who has 'use-only' access to a shared credential with configured domain restrictions, to bypass these restrictions. By leveraging an AI Agent's Multi-Modal Communication Protocol (MCP) tool and directing it to an arbitrary external URL, the user can force the n8n instance to send sensitive secrets from the restricted credential to an attacker-controlled server. This vulnerability facilitates unauthorized data exfiltration, compromising the confidentiality of sensitive information. The issue is contingent on the \u003ccode\u003eN8N_ENABLED_MODULES=agents\u003c/code\u003e environment variable being active and a relevant credential being shared.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated member-level user gains 'use-only' access to a shared n8n credential that has configured \u0026quot;Allowed HTTP Request Domains\u0026quot; restrictions.\u003c/li\u003e\n\u003cli\u003eThe attacker creates an AI Agent within the n8n instance.\u003c/li\u003e\n\u003cli\u003eThe attacker configures the AI Agent to utilize an MCP tool.\u003c/li\u003e\n\u003cli\u003eThe attacker points the MCP tool to an arbitrary, attacker-controlled external URL.\u003c/li\u003e\n\u003cli\u003eThe attacker runs the AI Agent, which attempts to communicate with the external URL using the shared credential.\u003c/li\u003e\n\u003cli\u003eDue to the vulnerability (CVE-2026-59207), the n8n AI Agents module fails to enforce the domain restrictions.\u003c/li\u003e\n\u003cli\u003eThe sensitive secret from the shared credential is sent to the attacker-controlled external server.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully exfiltrates the credential's secret.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-59207 leads to the unauthorized exfiltration of sensitive secrets, such as API keys, database credentials, or other authentication tokens stored within n8n credentials. While the advisory does not specify the number of victims or targeted sectors, any organization using n8n with the AI Agents module enabled and shared restricted credentials is at risk. If an attacker gains access to these secrets, they can use them to access other internal or external systems, escalate privileges, or further compromise the organization's infrastructure, leading to significant data breaches and potential financial or reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-59207 immediately by upgrading n8n instances to version 2.28.1 or later, or 2.27.4 or later, to address the vulnerability in the affected_products.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not possible, disable the AI Agents module by removing \u003ccode\u003eagents\u003c/code\u003e from the \u003ccode\u003eN8N_ENABLED_MODULES\u003c/code\u003e environment variable to mitigate the risk.\u003c/li\u003e\n\u003cli\u003eAudit and restrict credential sharing to fully trusted users only to minimize the blast radius of similar vulnerabilities.\u003c/li\u003e\n\u003cli\u003eReview existing n8n credentials with domain restrictions for any unexpected sharing relationships.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T21:59:10Z","date_published":"2026-07-22T21:59:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-ai-agents-bypass/","summary":"The n8n AI Agents module in versions prior to 2.27.4 and between 2.28.0 and 2.28.1 failed to enforce configured 'Allowed HTTP Request Domains' restrictions, allowing an authenticated member-level user with 'use-only' access to a shared credential to bypass these domain restrictions and exfiltrate sensitive secrets to an attacker-controlled server.","title":"n8n AI Agents Module Restriction Bypass via MCP Connector (CVE-2026-59207)","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-ai-agents-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:n8n:n8n:2.28.0:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}