Impact
n8n prior to version 2.8.0 contains a storage‑based cross‑site scripting flaw that permits authenticated users to inject arbitrary JavaScript into the OAuth2 credential Authorization URL field. When a victim, who is also a user of the same n8n instance, clicks the OAuth authorization button, the malicious script is executed in the victim’s browser session with the victim’s privileges. This reflects an input validation weakness catalogued as CWE‑79 and compromises confidentiality and integrity of the affected user’s session.
Affected Systems
The vulnerability affects the n8n workflow automation platform in all releases before 2.8.0. Any installation running a version older than 2.8.0 is susceptible to the flaw.
Risk and Exploitability
The flaw carries a CVSS score of 4.8, indicating moderate risk, and an EPSS score of less than 1 %, suggesting a low likelihood of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first be an authenticated user capable of creating a malicious credential and a separate victim who will engage with the OAuth button. Once the victim clicks the button, the stored script is executed in their browser session.
OpenCVE Enrichment