云虫漏洞库

CVE-2026-72771 - n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services. - 漏洞详情

漏洞编号:CVE-2026-72771

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-72771

CNNVD 编号:-

厂商/产品:n8n / n8n

影响范围:cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*

CWE:CWE-863

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.

相关链接

相关漏洞

« 返回首页