{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n-2.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (1.x)","n8n (2.x)"],"_cs_severities":["high"],"_cs_tags":["cross-site-scripting","xss","web-application","ghsa"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity DOM-based cross-site scripting (XSS) vulnerability (GHSA-vhcw-f978-xjjg) has been identified in the n8n workflow automation platform. Specifically, versions prior to 1.123.64 (for 1.x), 2.29.8, and 2.30.1 (for 2.x) are affected. The vulnerability lies within n8n's HTML preview functionality, which, when rendering execution output, uses an iframe \u003ccode\u003esrcdoc\u003c/code\u003e without the crucial \u003ccode\u003esandbox\u003c/code\u003e attribute. This oversight, combined with a sanitizer bypass, enables attackers holding \u003ccode\u003eglobal:member\u003c/code\u003e privileges to inject arbitrary JavaScript code. When a victim subsequently opens this manipulated preview, the injected script executes within the same-origin context as the n8n editor, effectively hijacking the victim's authenticated session and allowing unauthorized calls to n8n's internal APIs. This could lead to data exfiltration, workflow manipulation, or further compromise of the n8n environment. The vulnerability represents a significant risk for organizations using affected n8n instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker, possessing an account with \u003ccode\u003eglobal:member\u003c/code\u003e privileges in n8n, crafts malicious \u0026quot;execution output\u0026quot; containing JavaScript code designed for XSS exploitation.\u003c/li\u003e\n\u003cli\u003eThe attacker introduces this malicious output into the n8n environment, likely as part of a workflow execution result or a similar feature that generates previewable HTML.\u003c/li\u003e\n\u003cli\u003eA victim, typically another n8n user or administrator, accesses or is directed to open the HTML preview associated with the attacker-controlled execution output.\u003c/li\u003e\n\u003cli\u003eThe n8n application renders the preview using an \u003ccode\u003eiframe srcdoc\u003c/code\u003e element that lacks the \u003ccode\u003esandbox\u003c/code\u003e attribute, failing to isolate the content from the parent domain.\u003c/li\u003e\n\u003cli\u003eDue to an identified sanitizer bypass, the malicious JavaScript payload contained within the \u003ccode\u003esrcdoc\u003c/code\u003e is executed directly within the victim's browser, operating with the same-origin context as the n8n editor.\u003c/li\u003e\n\u003cli\u003eThe injected script leverages the victim's active authenticated session to invoke n8n's internal authenticated APIs.\u003c/li\u003e\n\u003cli\u003eThis allows the attacker to perform actions with the victim's privileges, such as exfiltrating sensitive data, altering existing workflows, creating new malicious workflows, or otherwise manipulating the n8n environment.\u003c/li\u003e\n\u003cli\u003eThe final objective is typically data exfiltration, unauthorized modification of configurations, or further lateral movement within the compromised n8n instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this XSS vulnerability allows an attacker to execute arbitrary code within the victim's browser session, operating with the same privileges as the victim. This enables the attacker to make unauthorized API calls within the n8n environment, potentially leading to data theft, modification or deletion of sensitive workflows, configuration changes, or escalation of privileges. Organizations using affected n8n instances could face significant operational disruption, data breaches, and compromise of their automation infrastructure, particularly if an administrator's session is hijacked. The specific number of victims and sectors targeted are not detailed in the advisory, but any n8n deployment utilizing the vulnerable versions is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances immediately to a patched version (1.123.64, 2.29.8, 2.30.1, or later) to address the vulnerability described in GHSA-vhcw-f978-xjjg.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for n8n for any unusual requests or patterns that might indicate attempts to introduce or trigger malicious content.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T17:56:59Z","date_published":"2026-07-22T17:56:59Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-xss/","summary":"A high-severity DOM-based cross-site scripting (XSS) vulnerability exists in n8n versions prior to 1.123.64, 2.29.8, and 2.30.1, allowing an attacker with global:member privileges to inject malicious JavaScript into an unsandboxed HTML preview, enabling same-origin execution and unauthorized API calls using a victim's session upon preview access.","title":"N8n DOM-based XSS via Unsandboxed iframe srcdoc in HTML Preview","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (2.x)","version":"https://jsonfeed.org/version/1.1"}