CVE-2026-54301
published 2026-06-23CVE-2026-54301: n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a…
PriorityP430medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.22%
12.0th percentile
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The binary response path bypassed the central Content-Security-Policy sandbox header, allowing a public webhook to execute JavaScript in the n8n origin when visited by an authenticated user, with access to that user's session. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| n8n-io | n8n | < 1.123.55 | 1.123.55 |
| n8n-io | n8n | — | — |
| n8n-io | n8n | — | — |
| n8n | n8n | < 1.123.55 | 1.123.55 |
| n8n | n8n | >= 0 < 1.123.55 | 1.123.55 |
| n8n | n8n | >= 2.0.0 < 2.25.7 | 2.25.7 |
| n8n | n8n | >= 2.0.0-rc.0 < 2.25.7 | 2.25.7 |
| n8n | n8n | >= 2.26.0 < 2.26.2 | 2.26.2 |
| n8n | n8n | >= 2.26.0 < 2.26.2 | 2.26.2 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.07.0HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
n8n-io n8n up to 1.123.54/2.25.6/2.26.1 Content-Security-Policy cross site scripting (GHSA-v733-mwr6-fgcm)
vuldb·2026-06-24·CVSS 7.0
CVE-2026-54301 [HIGH] n8n-io n8n up to 1.123.54/2.25.6/2.26.1 Content-Security-Policy cross site scripting (GHSA-v733-mwr6-fgcm)
A vulnerability marked as problematic has been reported in n8n-io n8n up to 1.123.54/2.25.6/2.26.1. The impacted element is an unknown function of the component Content-Security-Policy Handler. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-54301. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
n8n: Same-Origin XSS in Respond to Webhook Node
ghsa·2026-06-16
CVE-2026-54301 [HIGH] CWE-79 n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Same-Origin XSS in Respond to Webhook Node
## Impact
An authenticated user with workflow edit access could configure a `Respond to Webhook` node to serve binary content with an attacker-controlled `Content-Type`. The binary response path bypassed the central `Content-Security-Policy` sandbox header, allowing a public webhook to execute JavaScript in the n8n origin when visited by an authenticated user, with access to that user's session.
## Patches
The issue has been fixed in n8n versions 1.123.55, 2.25.7, and 2.26.2. Users should upgrade to one of these versions or later to remediate the vulnerability.
## Workarounds
If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
- Limit workflow creation and editing permissions to ful
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published