mediumCVSS 9.1Vulnerability

GHSA-3875-8gcx-7v46

## Impact The `POST /rest/dynamic-node-parameters/options` endpoint allowed any authenticated user to cause the n8n server to issue HTTP requests including credentials bypassing the intended restrictions on which hosts could be contacted for that credential (Allowed HTTP Request Domains). The user needed to be authenticated and have access to the credential. ## Patches The issue has been fixed in n8n version 2.20.0. Users should upgrade to this version or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n access to fully trusted users only. - Limit credential sharing to users who genuinely require access to those credentials. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Properties

ghsa_id
GHSA-3875-8gcx-7v46
severity
medium
summary
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
cvss_score
9.1
cve_id
GHSA-3875-8gcx-7v46
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
is_ghsa_only
true
ghsa_published
2026-05-19T16:17:43Z
source_url
https://github.com/advisories/GHSA-3875-8gcx-7v46
ghsa_updated
2026-05-19T16:17:44Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-3875-8gcx-7v46 (CVSS 9.1) — Ninja Signal Threat Intelligence | Ninja Signal