← volver
CVE-2026-54302

n8n: Stored XSS in Chat Trigger Node

CVSS 7 HIGHEPSS 0.2%CWE-79
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
23 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webhookId. When a logged-in user visited the chat URL, the injected code executed in the n8n origin with that user's session privileges. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
n8n-io · n8n

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →