Stored DOM Cross-Site Scripting in n8n by n8n-io
CVE-2026-103249

6.9MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103249?

The n8n automation platform has a stored DOM cross-site scripting vulnerability in its Resource Locator parameter dropdown handling. This issue allows workflow authors to inject malicious script URLs into the editor, which execute arbitrary JavaScript when other users interact with the node dropdown and click on the external-link icon. These malicious scripts can persist across workflow imports and shares, posing a significant risk to users of affected versions.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tr4ce-ju
.