Input validation error in n8n - #VU140995

 

Input validation error in n8n - #VU140995

Published: August 5, 2026


Vulnerability identifier: #VU140995
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in another user's authenticated session.

The vulnerability exists due to improper input validation in the resource-locator field link preview rendering logic when rendering a stored field value into the node type URL template. A remote user can store a malicious value containing expression syntax to execute arbitrary JavaScript in another user's authenticated session.

User interaction is required when another user opens the affected node in the editor.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.69, 2.33.4, 2.34.1

External References

Related Security Bulletins