PT-2026-78931 · N8N · N8N

·

CVE-2026-77075

·

Published

2026-08-20

·

Updated

2026-08-31

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.69 n8n versions 2.x prior to 2.33.4 n8n versions 2.34.x prior to 2.34.1
Description An expression injection issue exists in the link preview rendering of the resource-locator field. The editor directly splices the stored value of this field into the URL template of the node type without validating expression syntax. This allows an authenticated member to store a malicious value that, when viewed by another user in the editor, executes the injected expression as JavaScript within the victim's authenticated session, leading to cross-user script execution.
Recommendations Update to version 1.123.69 or later. Update to version 2.33.4 or later for the 2.x branch. Update to version 2.34.1 or later for the 2.34.x branch.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77075
GHSA-FH4C-9RR2-P7QC

Affected Products

N8N