CVE-2026-72768: n8n: SSRF bypass in MCP Client node exposes internal hosts

HIGH
Published August 11, 2026
CISO Take

A vulnerability in n8n's MCP Client node lets authenticated users bypass the platform's SSRF protections, letting a crafted workflow send requests to internal or otherwise blocked hosts and read the responses back through the workflow output. This matters because n8n is widely deployed as an orchestration layer for AI agents and automation, and the MCP Client node is specifically the component that lets agents call external tools and services — a compromised or malicious authenticated user could pivot from the n8n instance into internal networks, cloud metadata endpoints, or admin-only services that were never meant to be reachable. It's not currently in CISA KEV, there's no public exploit or Nuclei template, and CISA's SSVC decision is TRACK (lowest urgency tier), though EPSS places it in the top 86th percentile for exploitation likelihood among all scored CVEs. Exploitation requires an authenticated account, which caps the blast radius to insiders or attackers who've already obtained n8n credentials. Action: upgrade to n8n 2.32.1+ immediately, audit existing workflows for MCP Client nodes pointed at unexpected internal hosts, and restrict workflow-creation privileges to trusted users in the interim.

Sources: NVD GitHub Advisory EPSS ATLAS vulncheck.com

What is the risk?

Currently a moderate risk rather than critical: no public exploit code or scanner template exists, the CVE is absent from CISA KEV, and CISA's own SSVC decision (TRACK) places it in the lowest-urgency remediation tier. However, the EPSS score of 0.00228 still ranks in the top 86th percentile of all scored CVEs, indicating above-average future exploitation interest relative to the broader vulnerability population. The requirement for prior authentication is the main mitigating factor — this is not remotely exploitable by an anonymous attacker — but it becomes significant wherever n8n instances have multiple users with varying trust levels, or where attacker footholds (stolen credentials, compromised SSO) could reach the n8n UI.

How does the attack unfold?

Initial Access
Attacker obtains or already holds valid authenticated credentials to the n8n instance.
AML.T0012
Exploitation
Attacker crafts a workflow using the MCP Client node targeting an internal or normally-blocked host, bypassing n8n's SSRF protection.
AML.T0053
Data Collection
The workflow's request reaches the internal service and its response is captured within the workflow execution.
AML.T0086
Impact
Attacker reads the internal response data via the n8n UI or logs, exposing internal service data or credentials without direct network access.
AML.T0025

What systems are affected?

Package Ecosystem Vulnerable Range Patched
n8n npm — No patch
206.1K OpenSSF 6.7 Pushed 5d ago 53% patched ~5d to patch Full package profile →

Do you use n8n? You're affected.

How severe is it?

CVSS 3.1
8.3 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 31% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR Low
UI None
S Unchanged
C High
I High
A Low

What should I do?

1 step
  1. Upgrade n8n to version 2.32.1 or later, where the SSRF protection bypass is fixed. Until patched, restrict who can create or edit workflows containing MCP Client nodes to trusted, need-to-know users, and review existing workflows for MCP Client nodes configured against unexpected or internal-looking hostnames/IPs. Apply network-level egress filtering from the n8n host/workers so outbound requests to internal ranges (RFC1918, cloud metadata IPs like 169.254.169.254) are blocked regardless of application-layer SSRF controls. Monitor n8n execution logs and outbound network traffic for anomalous requests to internal services initiated by workflow executions, and rotate any credentials that may have been reachable via internal endpoints n8n workflows could reach.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact total

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

NIST AI RMF
MANAGE 2.3 - Manage risks from third-party AI system components
OWASP LLM Top 10
LLM07 - Insecure Plugin Design

Frequently Asked Questions

What is CVE-2026-72768?

A vulnerability in n8n's MCP Client node lets authenticated users bypass the platform's SSRF protections, letting a crafted workflow send requests to internal or otherwise blocked hosts and read the responses back through the workflow output. This matters because n8n is widely deployed as an orchestration layer for AI agents and automation, and the MCP Client node is specifically the component that lets agents call external tools and services — a compromised or malicious authenticated user could pivot from the n8n instance into internal networks, cloud metadata endpoints, or admin-only services that were never meant to be reachable. It's not currently in CISA KEV, there's no public exploit or Nuclei template, and CISA's SSVC decision is TRACK (lowest urgency tier), though EPSS places it in the top 86th percentile for exploitation likelihood among all scored CVEs. Exploitation requires an authenticated account, which caps the blast radius to insiders or attackers who've already obtained n8n credentials. Action: upgrade to n8n 2.32.1+ immediately, audit existing workflows for MCP Client nodes pointed at unexpected internal hosts, and restrict workflow-creation privileges to trusted users in the interim.

Is CVE-2026-72768 actively exploited?

No confirmed active exploitation of CVE-2026-72768 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-72768?

Upgrade n8n to version 2.32.1 or later, where the SSRF protection bypass is fixed. Until patched, restrict who can create or edit workflows containing MCP Client nodes to trusted, need-to-know users, and review existing workflows for MCP Client nodes configured against unexpected or internal-looking hostnames/IPs. Apply network-level egress filtering from the n8n host/workers so outbound requests to internal ranges (RFC1918, cloud metadata IPs like 169.254.169.254) are blocked regardless of application-layer SSRF controls. Monitor n8n execution logs and outbound network traffic for anomalous requests to internal services initiated by workflow executions, and rotate any credentials that may have been reachable via internal endpoints n8n workflows could reach.

What systems are affected by CVE-2026-72768?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow orchestration, tool/plugin integrations (MCP).

What is the CVSS score for CVE-2026-72768?

CVE-2026-72768 has a CVSS v3.1 base score of 8.3 (HIGH). The EPSS exploitation probability is 0.40%.

What is the AI security impact?

Affected AI Architectures

agent frameworksworkflow orchestrationtool/plugin integrations (MCP)

MITRE ATLAS Techniques

AML.T0012 Valid Accounts
AML.T0053 AI Agent Tool Invocation
AML.T0086 Exfiltration via AI Agent Tool Invocation

Compliance Controls Affected

NIST AI RMF: MANAGE 2.3
OWASP LLM Top 10: LLM07

What are the technical details?

Original Advisory

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back through the workflow.

Exploitation Scenario

An attacker who has obtained low-privilege but valid credentials to an n8n instance (via phishing, credential stuffing, or an insider with workflow-editing rights) creates a new workflow using the MCP Client node, configuring it to target an internal-only endpoint such as the cloud provider's instance metadata service or an internal admin API that the SSRF filter would normally block. Because the MCP Client node's request handling doesn't route through n8n's standard SSRF protection, the request reaches the blocked host directly. The workflow then surfaces the raw response — potentially containing IAM credentials, internal service data, or configuration secrets — in its output, which the attacker reads via the n8n UI or execution log, achieving internal reconnaissance and data exposure without ever touching the target host directly.

Weaknesses (CWE)

CWE-918 — Server-Side Request Forgery (SSRF): The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Timeline

Published
August 11, 2026
Last Modified
September 1, 2026
First Seen
August 11, 2026

Related Vulnerabilities