AE-E1MM1WST
AI agent MCP connector ignores a credential's allowed-domain restriction, sending the shared secret to an arbitrary URL
SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
n8n's AI Agents feature did not enforce the "Allowed HTTP Request Domains" restriction configured on credentials. A member-level user with use-only access to a shared credential could point an MCP tool at an arbitrary URL and run the agent, causing the credential's secret to be sent to a server they control.
- Framework / agent
- n8n · workflow-platform AI agent with MCP tools
- Remediation attempts
- APPLIEDSUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector — https://github.com/n8n-io/n8n, retrieved 2026-09-29
Symptoms
- A domain-restricted credential used by an agent's MCP tool is sent to a URL outside its allowed domains
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-E1MM1WST. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.