Junglewise Threat Intelligence

n8n stored DOM XSS in Resource Locator component

Severity: high · CVSS 8.4 · Published 2026-07-22

Technologies: N8n-Io N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect different software services. A security flaw in its Resource Locator component allows an attacker with workflow editing permissions to embed malicious scripts. If another user opens the compromised workflow and clicks an external link, the attacker could execute code in their browser, potentially leading to unauthorized data access or account takeover.

Technical details

A stored DOM cross-site scripting (XSS) vulnerability exists in n8n's Resource Locator component. The root cause is the lack of scheme validation for the 'cachedResultUrl' parameter before it is passed to the window.open() function. An attacker with workflow creation or editing privileges can inject a malicious URI scheme (such as 'javascript:') into this parameter. When a victim opens the affected workflow and interacts with external links, the payload executes within the context of the victim's browser session. This vulnerability is addressed in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n-io n8n < 1.123.64, 2.29.8, 2.30.1

Timeline

  • 2026-07-22: advisory: Initial publication of GHSA-h5xr-fqvj-253p
  • 2026-07-22: other: Advisory withdrawn as a duplicate of GHSA-9wcp-9r3j-383q

References

Related threats