Junglewise Threat Intelligence

n8n DOM-based XSS in HTML preview iframe

Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and execute automated tasks. The HTML preview feature renders output into an iframe without proper security sandbox protections, allowing attackers with basic user privileges to inject malicious scripts that execute with the same permissions as the victim's session. An attacker can exploit this to steal data or perform unauthorized actions on behalf of an authenticated user.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in n8n's HTML preview feature. The vulnerable component renders execution output into an unsandboxed iframe using the srcdoc attribute, and a sanitizer bypass allows injected scripts to execute in the same origin as the editor. The attack requires a user account with at least global:member privileges to craft a malicious workflow, and exploitation is triggered when a victim opens the HTML preview. Once exploited, the attacker can call authenticated APIs using the victim's session context, potentially accessing sensitive data or modifying workflows. Patches are available in versions 1.123.64, 2.29.8, and 2.30.1 and later.

Affected products

  • n8n n8n < 1.123.64, < 2.29.8, < 2.30.1

Timeline

  • 2026-07-08: disclosed
  • 2026-07-22: advisory

References

Related threats