{"id":"CVE-2026-77085","summary":"n8n before 2.34.1 SSRF Protection Bypass via SearXNG Tool","details":"n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On instances with N8N_SSRF_PROTECTION_ENABLED=true, an authenticated user with permission to create SearXNG credentials and configure a personal agent could set the API URL to an internal host, causing the n8n server to connect to that host and return the response content through the Agent chat output.","aliases":["GHSA-9rp2-wm75-c5fj"],"modified":"2026-08-23T03:42:26.849854996Z","published":"2026-08-20T11:21:15.741Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77085.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77085.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-9rp2-wm75-c5fj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77085"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/n8n-before-ssrf-protection-bypass-via-searxng-tool"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/n8n-io/n8n","events":[{"introduced":"b533ecd6856fef9ba7ca096d14b1f798b9933ff6"},{"fixed":"e2279d07cdc8d1aeee42607a15365ccfa98f8b27"},{"introduced":"a8ecda44f7627630bc8b78cf671405157ad41c4f"},{"fixed":"14c9aef0552fb4776501ca1c4589451891dd0ef4"}],"database_specific":{"extracted_events":[{"introduced":"2.34.0"},{"fixed":"2.34.1"},{"introduced":"2.0.0"},{"fixed":"2.33.4"}],"source":"AFFECTED_FIELD"}}],"versions":["n8n@2.34.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77085.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N"}]}