GHSA-vhcw-f978-xjjgHigh▾ TwilightDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-p3rg-hrf9-w9gj. This link is maintained to preserve external references.
n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call authenticated APIs using the victim's session. An account with global:member privileges can exploit the issue.
n8n < 1.123.64Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65597Highn8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-h5xr-fqvj-253pHighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65592Highn8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54302High· 7.6n8n: Stored XSS in Chat Trigger Node