PT-2026-63355 · N8N · N8N

·

CVE-2026-65597

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64 n8n versions prior to 2.29.8 n8n versions prior to 2.30.1
Description A DOM-based cross-site scripting issue exists in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected scripts to execute with the same origin as the editor. This enables an account with global:member privileges to call authenticated APIs using the victim's session when the preview is opened.
Recommendations Update to version 1.123.64 or later. Update to version 2.29.8 or later. Update to version 2.30.1 or later. Restrict instance access to fully trusted users only. Set the N8N CONTENT SECURITY POLICY environment variable to a policy that blocks inline scripts. Avoid exposing workflows that render externally-controlled input into the HTML node or binary HTML preview to untrusted users.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65597
GHSA-P3RG-HRF9-W9GJ
GHSA-VHCW-F978-XJJG

Affected Products

N8N