Server-side Request Forgery (SSRF) Affecting @n8n/n8n-nodes-langchain package, versions <2.31.3>=2.32.0 <2.32.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.23% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-N8NN8NNODESLANGCHAIN-18322497
  • published27 Jul 2026
  • disclosed22 Jul 2026
  • creditUnknown

Introduced: 22 Jul 2026

CVE-2026-72768  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade @n8n/n8n-nodes-langchain to version 2.31.3, 2.32.1 or higher.

Overview

@n8n/n8n-nodes-langchain is a Banner image

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the MCP Client. An attacker can access internal or otherwise restricted network resources by supplying crafted endpoints, causing the server to connect to unintended hosts and return sensitive responses through workflow execution.

Note: This is only exploitable if SSRF protection is enabled and the attacker has permissions to create or edit workflows.

Workaround

This vulnerability can be mitigated by restricting access to fully trusted users, disabling the MCP Client node via the NODES_EXCLUDE environment variable, or restricting network egress from the host to block internal and link-local address ranges.

CVSS Base Scores

version 4.0
version 3.1