Stored DOM Cross-Site Scripting in n8n by n8n-io
CVE-2026-103249
6.9MEDIUM
What is CVE-2026-103249?
The n8n automation platform has a stored DOM cross-site scripting vulnerability in its Resource Locator parameter dropdown handling. This issue allows workflow authors to inject malicious script URLs into the editor, which execute arbitrary JavaScript when other users interact with the node dropdown and click on the external-link icon. These malicious scripts can persist across workflow imports and shares, posing a significant risk to users of affected versions.
Affected Version(s)
n8n 0 < 1.123.80
n8n 2.0.0 < 2.39.6
n8n 2.40.0 < 2.40.1
