Open redirect in n8n - #VU128724

 

Open redirect in n8n - #VU128724

Published: April 30, 2026


Vulnerability identifier: #VU128724
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect end users to an arbitrary external URL.

The vulnerability exists due to an overly permissive iframe sandbox policy in the Form Node when rendering form content. A remote user can configure a crafted form to redirect end users to an arbitrary external URL.

User interaction is required when an end user visits the form.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.24, 2.10.4, 2.12.0

External References

Related Security Bulletins