{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/n8n--2.37.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-86082"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (\u003c 1.123.76, \u003e= 2.0.0 \u003c 2.37.7, \u003e= 2.38.0 \u003c 2.38.2)","n8n (\u003c 2.37.7)","n8n (2.38.0 - 2.38.1)","n8n (\u003c 1.123.76)","n8n (2.0.0 - 2.37.6)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","webserver","credential-theft","n8n","cve-2026-86082","denial-of-service","web-vulnerability","cve-2026-86076","javascript","sandbox-escape"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH","n8n"],"content_html":"\u003cp\u003eA security vulnerability in n8n (CVE-2026-86082) allows authenticated users to bypass configured domain restrictions within the OpenAI Chat Model node. While the primary OpenAI request path correctly validated custom base URLs against allowed-domain configurations, the secondary model-search dropdown endpoint failed to perform this check. An attacker able to manipulate request options could define a custom base URL that directed sensitive requests to an arbitrary, attacker-controlled host while still including the original, valid OpenAI credentials. This flaw enables the exfiltration of API keys or the use of credentials against unauthorized third-party infrastructure. This vulnerability affects multiple versions of n8n across the 1.x and 2.x branches and necessitates a prompt upgrade to the patched versions to ensure consistent credential protection across all API call sites.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized use of OpenAI credentials by routing requests to external hosts, potentially leading to credential exposure or unauthorized usage of services. If compromised, an attacker can leverage these credentials to make unauthorized API calls. Security teams should assume any n8n instance with domain-restricted OpenAI credentials might have been subject to credential exposure if the instance was accessible to untrusted users prior to patching.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n to version 1.123.76, 2.37.7, 2.38.2, or later to implement centralized domain validation for all OpenAI call sites.\u003c/li\u003e\n\u003cli\u003eRotate all OpenAI API keys currently stored in n8n instances if there is suspicion of unauthorized access or exposure via this vector.\u003c/li\u003e\n\u003cli\u003eReview OpenAI account usage logs for any traffic originating from unexpected or unauthorized endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict access to the n8n instance to trusted users until the software is patched.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T00:54:58Z","date_published":"2026-09-10T18:53:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-n8n-domain-bypass/","summary":"An unauthenticated credential access vulnerability in n8n allows users to bypass domain restrictions in the OpenAI Chat Model node via the model-search endpoint, leading to unauthorized credential exposure.","title":"Domain-Restriction Bypass in n8n OpenAI Chat Model Node","url":"https://feed.craftedsignal.io/briefs/2026-09-n8n-domain-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (\u003c 2.37.7)","version":"https://jsonfeed.org/version/1.1"}