Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back through the workflow. | |
| Title | n8n before 2.32.1 SSRF Protection Bypass via MCP Client | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T18:02:34.479Z
Reserved: 2026-08-10T15:06:16.417Z
Link: CVE-2026-72768
Updated: 2026-08-11T18:02:23.715Z
Status : Received
Published: 2026-08-11T13:19:07.077
Modified: 2026-08-11T18:18:24.757
Link: CVE-2026-72768
No data.
OpenCVE Enrichment
No data.