Junglewise Threat Intelligence

CVE-2026-25054: n8n stored cross-site scripting in markdown rendering

CVE-2026-25054 · Severity: medium · CVSS 4 · Published 2026-02-04

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and share automation workflows. A stored cross-site scripting vulnerability in the markdown rendering component could allow an authenticated attacker to inject malicious code into workflow sticky notes and other markdown areas. When other users view an affected workflow, the injected code executes in their browser with full privileges, potentially leading to account takeover and session hijacking.

Technical details

The vulnerability is a stored XSS (CWE-79) in n8n's markdown rendering component, specifically affecting workflow sticky notes and other markdown-enabled areas in the workflow UI. An authenticated user with permission to create or modify workflows can inject arbitrary JavaScript code into markdown content. When other users interact with or view the malicious workflow, the injected script executes in their browser context with the same origin privileges, enabling session hijacking and account takeover. Attack vector is network-based and requires the attacker to have authenticated access with workflow creation/modification privileges, plus user interaction (a victim opening the affected workflow). The vulnerability was fixed in versions 2.2.1 and 1.123.9.

Affected products

  • n8n n8n before 1.123.9 and before 2.2.1

Timeline

  • 2026-02-04: disclosed
  • 2026-02-04: patched: Fixed in versions 2.2.1 and 1.123.9

References

Related threats