THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q5wm-mgqx-fv2f (medium) — n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

[GHSA] GHSA-q5wm-mgqx-fv2f (medium) — n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

medgithub_advisoriesPublished 2026-09-10

GHSA-q5wm-mgqx-fv2f Severity: medium CVE: CVE-2026-86074

n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

## Impact

Instance AI credential setup accepted a credential test/verification URL without checking it matched the workflow node's origin. Exfiltration required the user to actively inject an attacker-controlled URL into the setup flow. The patch derives

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q5wm-mgqx-fv2f