n8n
cpe:2.3:a:n8n:n8n:*:*:*:*:node.js:*:*
- < 2.8.0
- < 2.6.4
A cross-site scripting vulnerability has been identified in n8n versions prior to 2.8.0 and 2.6.4. This issue allows authenticated users to inject malicious JavaScript URLs into the Authorization URL fields of OAuth2 credentials. Attackers can create harmful credentials and persuade victims to click the OAuth authorization button, which would execute the injected scripts in the context of the victim's browser session.
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's session, potentially leading to unauthorized actions or data exposure.
Users should upgrade to n8n version 2.8.0 or 2.6.4 and later. If an immediate upgrade is not possible, consider limiting credential creation and sharing permissions to trusted users and restricting access to the n8n instance to trusted users only.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.