CVE-2026-65592
EUVD-2026-4763622.07.2026, 12:18
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| n8n | n8n | 𝑥 < 1.123.64 |
| n8n | n8n | 𝑥 < 1.123.64 |
| n8n | n8n | 2.0.0 ≤ 𝑥 < 2.29.8 |
| n8n | n8n | 2.0.0 ≤ 𝑥 < 2.29.8 |
| n8n | n8n | 2.30.0 |
| n8n | n8n | 2.30.0 |
𝑥
= Vulnerable software versions