Input validation error in n8n - #VU140995
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's authenticated session.
The vulnerability exists due to improper input validation in the resource-locator field link preview rendering logic when rendering a stored field value into the node type URL template. A remote user can store a malicious value containing expression syntax to execute arbitrary JavaScript in another user's authenticated session.
User interaction is required when another user opens the affected node in the editor.