Junglewise Threat Intelligence

CVE-2025-46343: n8n stored XSS through attachments view endpoint

CVE-2025-46343 · Severity: low · CVSS 3.1 · Published 2025-04-28

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to build and execute automated business processes. The platform stores binary file attachments that are accessible to authenticated users. An attacker with basic member-level access could upload a malicious HTML file, which when accessed by another user through a specially crafted link, would execute arbitrary JavaScript in the victim's browser session—enabling account takeover or unauthorized account modifications.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in n8n's attachments view endpoint. The root cause is the lack of MIME type validation on uploaded files combined with user-controllable MIME type specification via GET parameters. An authenticated attacker with member-level permissions can upload a crafted HTML file containing malicious JavaScript. When another user accesses the binary data endpoint with a MIME type parameter set to "text/html", the server serves the file with that content type, causing the browser to interpret and execute the embedded script in the context of the user's authenticated session. Attack preconditions include valid n8n authentication and member-level permissions. Patches are available in n8n version 1.90.0 and later.

Affected products

  • n8n n8n <1.90.0

Timeline

  • 2025-04-28: disclosed: GHSA-c8hm-hr8h-5xjw published
  • 2025-04-29: advisory: CVE-2025-46343 published by NVD
  • 2025-04-28: patched: Fix released in n8n version 1.90.0

References

Related threats