CVE-2026-72768

Source
https://cve.org/CVERecord?id=CVE-2026-72768
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72768.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72768
Aliases
Downstream
Published
2026-08-11T12:17:08Z
Modified
2026-09-03T03:48:19Z
Severity
  • 6.4 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L CVSS Calculator
Summary
n8n before 2.32.1 SSRF Protection Bypass via MCP Client
Details

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back through the workflow.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72768.json"
}
References

Affected packages

Git / github.com/n8n-io/n8n

Affected ranges

Type
GIT
Repo
https://github.com/n8n-io/n8n
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:n8n:n8n:2.32.0:*:*:*:*:node.js:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.31.0"
        },
        {
            "fixed": "2.31.5"
        },
        {
            "introduced": "2.32.0"
        },
        {
            "last_affected": "2.32.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

2.*
2.32.0
n8n@2.*
n8n@2.31.0
n8n@2.31.1
n8n@2.31.2
n8n@2.31.3
n8n@2.32.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72768.json"