Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

n8n MCP Client SSRF Protection Bypass

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections and access internal services.

Disclosed 11 August 2026 · Record updated 13 September 2026

Impact

Authenticated users can bypass SSRF protections to send requests to internal or blocked hosts and read responses through workflows, exposing internal services.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-72768