Impact
The vulnerability is a stored DOM XSS in n8n's Resource Locator dropdown link handling. Authoring a workflow that contains a malicious script URL causes arbitrary JavaScript to execute in the editor's origin when another user opens the node dropdown and clicks the external‑link icon. The payload persists across workflow imports and shares, giving the attacker permanent exposure to affected participants.
Affected Systems
Affected versions are n8n prior to 1.123.80, 2.39.6, and 2.40.1, for all releases from 2.0.0 onward. The product is distributed by n8n‑io under the name n8n.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available; the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that an attacker first create or upload a workflow containing the malicious URL, then a victim must view that workflow or import it. The JavaScript runs in the victim’s browser, impacting their session data and potential access to other workflows. Based on the description, it is inferred that the attack may target confidentiality and integrity of the victim’s data. As the attack vector is user‑driven rather than network‑directed, the overall likelihood of exploitation is moderate, but the impact can be significant for organizations that share and reuse workflows.
OpenCVE Enrichment