GHSA-h5xr-fqvj-253pHigh▾ TwilightDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-9wcp-9r3j-383q. This link is maintained to preserve external references.
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser.
n8n < 1.123.64Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65592Highn8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-vhcw-f978-xjjgHighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65597Highn8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54302High· 7.6n8n: Stored XSS in Chat Trigger Node