Server-side Request Forgery (SSRF) Affecting @n8n/ai-utilities package, versions <0.24.3>=0.25.0 <0.25.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-N8NAIUTILITIES-20186758
  • published28 Sept 2026
  • disclosed20 Aug 2026
  • creditUnknown

Introduced: 20 Aug 2026

CVE-2026-77085  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade @n8n/ai-utilities to version 0.24.3, 0.25.1 or higher.

Overview

@n8n/ai-utilities is an Utilities for building AI nodes in n8n

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the searxngSearch function in packages/@n8n/ai-utilities/src/web-search/searxng-search.ts, which issues its request to the credential's API URL with the global fetch rather than a client carrying the centralized SSRF policy, so the URL is never validated against it. A user with permission to create SearXNG credentials and configure a personal agent can make the server connect to an internal host and read the response, by setting that credential's API URL to the internal address and reading the Agent chat output. This requires an authenticated account with those two permissions, and it matters specifically on instances running with N8N_SSRF_PROTECTION_ENABLED=true, where the request would otherwise be screened.

CVSS Base Scores

version 4.0
version 3.1