Improper Neutralization of Alternate XSS Syntax in n8n - CVE-2026-42235
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's authenticated browser session.
The vulnerability exists due to improper neutralization of alternate XSS syntax in the MCP OAuth client consent and revocation notification flow when rendering a crafted client_name. A remote attacker can register a malicious MCP OAuth client to execute arbitrary JavaScript in a victim's authenticated browser session.
User interaction is required to authorize the OAuth consent dialog and click the rendered link in the toast notification.