Arbitrary JavaScript Injection in n8n Workflow Automation Platform
CVE-2026-54302

7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54302?

The n8n Workflow Automation Platform is vulnerable to an arbitrary JavaScript injection when an authenticated user with workflow edit access sets a malicious webhookId. This allows the injected JavaScript code to execute with the session privileges of any logged-in user who visits the affected chat URL. The vulnerability affects versions prior to 1.123.55, 2.25.7, and 2.26.2, and it has been patched in the latest releases. Users are urged to update their installations to safeguard against potential exploitation.

Affected Version(s)

n8n < 1.123.55 < 1.123.55

n8n >= 2.0.0-rc.0, < 2.25.7 < 2.0.0-rc.0, 2.25.7

n8n >= 2.26.0, < 2.26.2 < 2.26.0, 2.26.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.