PT-2026-63350 · N8N · N8N

·

CVE-2026-65592

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64 n8n versions prior to 2.29.8 n8n versions prior to 2.30.1
Description A stored DOM cross-site scripting issue exists in the Resource Locator component. The component passes the workflow-persisted cachedResultUrl parameter to the window.open() function without validating the scheme. An attacker with privileges to create or edit workflows can include a malicious scheme, such as javascript:, in the cachedResultUrl variable. When a victim opens the crafted workflow and interacts with external links, the payload executes within the victim's browser.
Recommendations Update to version 1.123.64 or later. Update to version 2.29.8 or later. Update to version 2.30.1 or later. Restrict workflow creation and editing permissions to fully trusted users only. Audit existing workflows for unexpected cachedResultUrl values containing non-HTTP(S) schemes.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65592
GHSA-9WCP-9R3J-383Q
GHSA-H5XR-FQVJ-253P

Affected Products

N8N