PT-2026-50169 · N8N · N8N

·

CVE-2026-54303

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.24.0
Description An endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers. This allows for reflected Cross-Site Scripting (XSS), where an attacker can execute malicious scripts in the n8n origin if a logged-in user visits a specially crafted URL.
Recommendations Update to version 2.24.0 or later. Limit workflow creation and activation permissions to fully trusted users only. Disable the affected nodes by adding n8n-nodes-base.facebookTrigger, n8n-nodes-base.whatsAppTrigger, n8n-nodes-base.facebookLeadAdsTrigger, and n8n-nodes-base.microsoftTeamsTrigger to the NODES EXCLUDE environment variable.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54303
GHSA-H86Q-FX34-GFJR

Affected Products

N8N