PT-2026-6260 · N8N · N8N

Weblover12

·

Published

2026-02-04

·

Updated

2026-02-04

·

CVE-2026-25051

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.2
Description n8n is a workflow automation platform. A Cross-Site Scripting (XSS) issue exists in the handling of webhook responses and related HTTP endpoints. The Content Security Policy (CSP) sandbox protection may not be applied correctly under certain conditions. An authenticated user with appropriate permissions could exploit this to execute malicious scripts with same-origin privileges when other users interact with a crafted workflow, potentially leading to session hijacking and account takeover.
Recommendations Update to version 1.123.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-02166
CVE-2026-25051
GHSA-825Q-W924-XHGX

Affected Products

N8N