PT-2025-33750 · N8N · N8N
Agustedone
+3
·
Published
2025-08-19
·
Updated
2025-08-24
·
CVE-2025-52478
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
n8n versions 1.77.0 through 1.98.1
Description:
n8n is a workflow automation platform. A stored Cross-Site Scripting (XSS) vulnerability exists in the Form Trigger node's HTML form element. An authenticated attacker can inject malicious HTML via an
<iframe> with a srcdoc payload that includes arbitrary JavaScript execution. The attacker can also inject malicious Javascript by using <video> coupled with <source> using an onerror event. This allows for Account Takeover (ATO) by exfiltrating n8n-browserId and session cookies from authenticated users who visit a maliciously crafted form. Using these tokens and cookies, an attacker can impersonate the victim and change account details, such as email addresses, enabling full control over the account, especially if two-factor authentication is not enabled.Recommendations:
Upgrade to version 1.98.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N