Cross-site scripting in n8n - #VU150761
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the editor origin.
The vulnerability exists due to improper URL scheme validation in Resource Locator dropdown link handling when processing stored Resource Locator URLs. A remote user can set a Resource Locator parameter to a script URL in a workflow to execute arbitrary JavaScript in the editor origin.
User interaction is required to open the node\'s dropdown and click the external-link icon.