Cross-site scripting in n8n - #VU153008
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the n8n origin.
The vulnerability exists due to improper neutralization of active content in the binary-data file-preview modal when previewing a crafted uploaded binary-data item. A remote user can upload a crafted item for a victim to preview to execute arbitrary script in the n8n origin.
User interaction is required to preview the crafted item.