CVE-2026-65592
Severity CVSS v4.0:
HIGH
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
22/07/2026
Last modified:
27/07/2026
Description
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:* | 1.123.64 (excluding) | |
| cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* | 1.123.64 (excluding) | |
| cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:* | 2.0.0 (including) | 2.29.8 (excluding) |
| cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* | 2.0.0 (including) | 2.29.8 (excluding) |
| cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:community:node.js:*:* | ||
| cpe:2.3:a:n8n:n8n:2.30.0:*:*:*:enterprise:node.js:*:* |
To consult the complete list of CPE names with products and versions, see this page



