Cross-site scripting in n8n - #VU153008

 

Cross-site scripting in n8n - #VU153008

Published: September 30, 2026


Vulnerability identifier: #VU153008
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the n8n origin.

The vulnerability exists due to improper neutralization of active content in the binary-data file-preview modal when previewing a crafted uploaded binary-data item. A remote user can upload a crafted item for a victim to preview to execute arbitrary script in the n8n origin.

User interaction is required to preview the crafted item.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.83, 2.41.4, 2.42.1

External References

Related Security Bulletins