mediumVulnerability

GHSA-38fj-36m5-783c

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-9w78-79q7-r4fp. This link is maintained to preserve external references. ## Original Description n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.

Properties

ghsa_id
GHSA-38fj-36m5-783c
severity
medium
summary
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
cve_id
GHSA-38fj-36m5-783c
is_ghsa_only
true
ghsa_published
2026-07-22T12:32:17Z
source_url
https://github.com/advisories/GHSA-38fj-36m5-783c
ghsa_updated
2026-07-22T22:00:29Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-38fj-36m5-783c — Ninja Signal Threat Intelligence | Ninja Signal