Beveiligingsadvies

CVE-2026-54303

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-23 15:32:06
Laatst bijgewerkt 2026-06-24 13:52:23
Toegewezen door GitHub_M
CVSS-score 6.8
Status PUBLISHED

Beschrijving

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflected XSS in the n8n origin when a logged-in user visits a crafted URL. This vulnerability is fixed in 2.24.0.