GHSA-gq66-9cw5-j5jm: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Summary
The GraphQL node in n8n (a workflow automation tool) had a security flaw where it didn't properly enforce "Allowed HTTP Request Domains" restrictions on certain types of credentials (authentication methods like API keys and passwords), even though the regular HTTP Request node did. This meant that someone with permission to create workflows could potentially steal these restricted credentials by sending them to a server they control.
Solution / Mitigation
The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators can temporarily: restrict workflow creation and editing permissions to fully trusted users only, restrict credential sharing to fully trusted users only, and audit credentials with domain restrictions for unexpected sharing relationships. However, these workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Vulnerability Details
EPSS: 0.0%
Yes
July 22, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-gq66-9cw5-j5jm
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%