PT-2026-56436 · N8N · N8N
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.8.0
Description
A cross-site scripting issue exists in the credential management flow. Authenticated users can inject malicious JavaScript URLs into the OAuth2 credential Authorization URL fields. This allows an attacker to craft malicious credentials and trick victims into clicking the OAuth authorization button, which executes arbitrary scripts in the victim's browser session using their privileges.
Recommendations
Update n8n to version 2.8.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N