{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n--2.30.0--2.30.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-65592"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (\u003c 1.123.64)","n8n (\u003e= 2.0.0-rc.0, \u003c 2.29.8)","n8n (\u003e= 2.30.0, \u003c 2.30.1)","n8n (\u003c 2.29.8)","n8n (\u003c 2.30.1)"],"_cs_severities":["high"],"_cs_tags":["xss","vulnerability","n8n"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH","n8n"],"content_html":"\u003cp\u003eA high-severity stored DOM XSS vulnerability, identified as CVE-2026-65592, exists in the n8n workflow automation platform's Resource Locator feature. This flaw affects versions prior to 1.123.64, versions 2.0.0-rc.0 through 2.29.7, and version 2.30.0. Attackers can exploit this by injecting malicious JavaScript into the \u003ccode\u003ecachedResultUrl\u003c/code\u003e parameter within a crafted workflow. The vulnerability stems from a lack of scheme validation when \u003ccode\u003ecachedResultUrl\u003c/code\u003e is passed to \u003ccode\u003ewindow.open()\u003c/code\u003e. When a victim opens such a workflow and interacts with external links, the injected JavaScript executes in their browser. This allows for potential session hijacking, data exfiltration, or further client-side compromise, making it critical for defenders to prioritize upgrading to patched versions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to an n8n instance with privileges to create or edit workflows.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious JavaScript payload and embeds it within the \u003ccode\u003ecachedResultUrl\u003c/code\u003e parameter of an n8n workflow.\u003c/li\u003e\n\u003cli\u003eThe attacker saves the specially crafted workflow onto the vulnerable n8n instance.\u003c/li\u003e\n\u003cli\u003eA victim user opens the compromised workflow in their browser, loading the malicious \u003ccode\u003ecachedResultUrl\u003c/code\u003e value into the DOM.\u003c/li\u003e\n\u003cli\u003eThe victim interacts with an external link within the workflow, triggering the \u003ccode\u003ewindow.open()\u003c/code\u003e function that uses the unvalidated \u003ccode\u003ecachedResultUrl\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe embedded JavaScript payload executes within the victim's browser context, bypassing same-origin policies.\u003c/li\u003e\n\u003cli\u003eThe attacker's script performs actions such as session hijacking, data exfiltration, or further client-side exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65592 allows an attacker to execute arbitrary JavaScript within a victim's browser context. This can lead to various severe consequences, including session hijacking, unauthorized access to the victim's n8n account, data exfiltration of sensitive information displayed in the n8n interface, or further client-side exploitation through drive-by downloads or credential harvesting. While no specific victim numbers are provided, any user interacting with a compromised workflow could be affected, posing a significant risk to organizations using vulnerable n8n instances. The primary impact is on the confidentiality and integrity of user data within the affected n8n instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediately patch n8n instances to versions 1.123.64, 2.29.8, 2.30.1, or later to address CVE-2026-65592. As a temporary mitigation, restrict workflow creation and editing permissions in n8n to only trusted users. Implement application-level auditing to identify workflows containing unexpected \u003ccode\u003ecachedResultUrl\u003c/code\u003e values with non-HTTP(S) schemes, as detailed in the workarounds section of the advisory for CVE-2026-65592.\u003c/p\u003e\n","date_modified":"2026-07-22T18:06:12Z","date_published":"2026-07-22T18:02:15Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-stored-dom-xss/","summary":"A stored DOM XSS vulnerability in n8n's Resource Locator feature allows attackers to inject malicious JavaScript into the cachedResultUrl parameter. When a victim opens a specially crafted workflow and interacts with external links, the JavaScript payload executes in their browser, due to a lack of scheme validation for `cachedResultUrl` passed to `window.open()`.","title":"n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-stored-dom-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (\u003e= 2.30.0, \u003c 2.30.1)","version":"https://jsonfeed.org/version/1.1"}