CVE-2026-85172 | n8n-io n8n up to 2.34.0 Request Helper legacy request helper function uri/url server-side request forgery

SecurityVulns

A vulnerability identified as critical has been detected in n8n-io n8n up to 2.34.0. The affected element is the function legacy request helper function of the component Request Helper. The manipulation of the argument uri/url leads to server-side request forgery.

This vulnerability is listed as CVE-2026-85172. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More