DOM-Based Cross-Site Scripting in n8n by n8n.io
CVE-2026-65597

8.2HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-65597?

n8n, an automation tool, is susceptible to a DOM-based cross-site scripting attack due to improper handling of HTML preview output in certain versions. This vulnerability enables attackers to exploit an unsandboxed iframe, allowing malicious scripts to execute within the same origin as the n8n editor. Consequently, if a user accesses the HTML preview while logged in, the injected script can call authenticated APIs using the victim's session credentials. This issue is particularly concerning for accounts with elevated privileges, such as global:member, which can further amplify the potential impact.

Affected Version(s)

n8n 0 < 1.123.64

n8n 0 < 2.30.1

n8n 0 < 2.29.8

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

odgrso
.