CVE-2026-103249 PUBLISHED

n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 01.10.2026 Updated: 01.10.2026

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 6.9

Product Status

Vendor n8n-io
Product n8n
Versions Default: unaffected
  • affected from 0 to 1.123.80 (excl.)
  • affected from 2.0.0 to 2.39.6 (excl.)
  • affected from 2.40.0 to 2.40.1 (excl.)

Credits

  • tr4ce-ju reporter

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE