Executive brief
n8n is a workflow automation platform that allows users to create and execute automated tasks. A stored cross-site scripting (XSS) vulnerability in the "Respond to Webhook" node allows attackers with workflow creation permissions to inject malicious scripts that execute in the editor interface. This can be exploited to steal sensitive workflow data, modify workflows, or perform unauthorized actions within a user's authenticated session.
Technical details
The vulnerability is a stored XSS flaw (CWE-79) in n8n's "Respond to Webhook" node. When the node responds with HTML content containing executable scripts, the payload may execute directly in the top-level window instead of within the sandbox introduced in version 1.103.0. The attack requires network access and low privilege level (workflow creation permissions) plus user interaction. An attacker can inject malicious workflows that, when viewed by a victim, execute arbitrary JavaScript in the n8n editor context. Although session cookies (n8n-auth) are marked HttpOnly, the vulnerability enables CSRF-like attacks including unauthorized reading of workflow data/execution history, modification or deletion of workflows, and insertion of malicious logic. The vulnerability affects all versions prior to 1.114.0, which contains the fix.
Affected products
- n8n n8n < 1.114.0
Timeline
- 2025-12-26: disclosed: GHSA-58jc-rcg5-95f3 published
- 2025-12-26: patched: Patch released in version 1.114.0