Arbitrary JavaScript Injection in n8n Workflow Automation Platform
CVE-2026-54302
7HIGH
What is CVE-2026-54302?
The n8n Workflow Automation Platform is vulnerable to an arbitrary JavaScript injection when an authenticated user with workflow edit access sets a malicious webhookId. This allows the injected JavaScript code to execute with the session privileges of any logged-in user who visits the affected chat URL. The vulnerability affects versions prior to 1.123.55, 2.25.7, and 2.26.2, and it has been patched in the latest releases. Users are urged to update their installations to safeguard against potential exploitation.
Affected Version(s)
n8n < 1.123.55 < 1.123.55
n8n >= 2.0.0-rc.0, < 2.25.7 < 2.0.0-rc.0, 2.25.7
n8n >= 2.26.0, < 2.26.2 < 2.26.0, 2.26.2
