CVE-2026-103249High· 7.6▾ Twilightn8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious scr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
GHSA-h5xr-fqvj-253pHighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-vhcw-f978-xjjgHighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65597Highn8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65592Highn8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints