DOM-Based Cross-Site Scripting in n8n by n8n.io
CVE-2026-65597
8.2HIGH
What is CVE-2026-65597?
n8n, an automation tool, is susceptible to a DOM-based cross-site scripting attack due to improper handling of HTML preview output in certain versions. This vulnerability enables attackers to exploit an unsandboxed iframe, allowing malicious scripts to execute within the same origin as the n8n editor. Consequently, if a user accesses the HTML preview while logged in, the injected script can call authenticated APIs using the victim's session credentials. This issue is particularly concerning for accounts with elevated privileges, such as global:member, which can further amplify the potential impact.
Affected Version(s)
n8n 0 < 1.123.64
n8n 0 < 2.30.1
n8n 0 < 2.29.8
