THREAT OPS › Threat News › [GHSA] GHSA-34ff-336r-5q23 (high) — n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
[GHSA] GHSA-34ff-336r-5q23 (high) — n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
GHSA-34ff-336r-5q23 Severity: high CVE: CVE-2026-86082
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
## Impact
The OpenAI Chat Model node checked a custom base URL against the credential's allowed-domains configuration before sending a request, but the model-search dropdown did not. A request setting `options.baseURL` on that path reached an arbitr
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-86082cve
Original source: https://github.com/advisories/GHSA-34ff-336r-5q23