PT-2026-63355 · N8N · N8N
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.64
n8n versions prior to 2.29.8
n8n versions prior to 2.30.1
Description
A DOM-based cross-site scripting issue exists in the HTML preview, which renders execution output into an
iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected scripts to execute with the same origin as the editor. This enables an account with global:member privileges to call authenticated APIs using the victim's session when the preview is opened.Recommendations
Update to version 1.123.64 or later.
Update to version 2.29.8 or later.
Update to version 2.30.1 or later.
Restrict instance access to fully trusted users only.
Set the
N8N CONTENT SECURITY POLICY environment variable to a policy that blocks inline scripts.
Avoid exposing workflows that render externally-controlled input into the HTML node or binary HTML preview to untrusted users.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N