Cross-site scripting in n8n - #VU150761

 

Cross-site scripting in n8n - #VU150761

Published: September 17, 2026


Vulnerability identifier: #VU150761
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the editor origin.

The vulnerability exists due to improper URL scheme validation in Resource Locator dropdown link handling when processing stored Resource Locator URLs. A remote user can set a Resource Locator parameter to a script URL in a workflow to execute arbitrary JavaScript in the editor origin.

User interaction is required to open the node\'s dropdown and click the external-link icon.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.80, 2.39.6, 2.40.1

External References

Related Security Bulletins