PT-2025-53603 · N8N · N8N

Nlgbao1340

·

Publicado

2025-12-26

·

Atualizado

2025-12-31

·

CVE-2025-61914

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.114.0
Description n8n is a workflow automation platform. A stored Cross-Site Scripting (XSS) issue may occur when using the “Respond to Webhook” node in versions before 1.114.0. If this node responds with HTML content containing executable scripts, the payload may execute directly in the top-level window. This can allow a malicious actor with workflow creation permissions to execute arbitrary JavaScript in the n8n editor interface.
Recommendations Restrict workflow creation and modification privileges to trusted users only. Avoid using untrusted HTML responses in the “Respond to Webhook” node. Use an external reverse proxy or HTML sanitizer to filter responses that include executable scripts.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-61914
GHSA-58JC-RCG5-95F3

Produtos afetados

N8N