GHSA-q5wm-mgqx-fv2f: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Summary
A vulnerability in n8n's Instance AI credential setup allowed attackers to redirect credential verification requests to uncontrolled URLs, potentially stealing credentials if a user injected a malicious URL into the setup process. The flaw happened because the system didn't check that verification URLs matched the workflow node's origin (the source server where the code is running).
Solution / Mitigation
The issue has been fixed in n8n versions 2.38.2 and 2.37.7. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators can: (1) Disable the Instance AI module by removing `instance-ai` from the `N8N_ENABLED_MODULES` environment variable if not required; (2) Restrict n8n instance access to fully trusted users only; (3) Rotate any third-party API credentials that were set up using the Instance AI credential-setup flow on affected versions. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Vulnerability Details
EPSS: 0.4%
Yes
September 10, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-q5wm-mgqx-fv2f
First tracked: September 10, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%