NPM · JULY 2026 · CONFIRMED

n8n npm Package SSRF Vulnerability: Critical Update Required

GHSA-38FJ-36M5-783CGHSA-9W78-79Q7-R4FPSeverity: HIGH

n8n versions before 1.123.64 contain a server-side request forgery vulnerability that allows authenticated attackers to make the n8n server issue HTTP requests to arbitrary internal targets.

What happened

The vulnerability exists in the dynamic-node-parameters endpoints due to a lack of authorization scopes. When SSRF protection is disabled, attackers can supply absolute URLs in routing configuration to override baseURL restrictions.

This issue has been confirmed by multiple independent sources and is tracked under GHSA-38FJ-36M5-783C and GHSA-9W78-79Q7-R4FP. The recommended action to mitigate this vulnerability is to upgrade to n8n version 1.123.64 or later.

For more detailed information, please consult the primary sources listed in the threat data section.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats