n8n Cross-Site Scripting Vulnerability in OAuth2 Credential Management

Vulnerability

A cross-site scripting vulnerability has been identified in n8n versions prior to 2.8.0 and 2.6.4. This issue allows authenticated users to inject malicious JavaScript URLs into the Authorization URL fields of OAuth2 credentials. Attackers can create harmful credentials and persuade victims to click the OAuth authorization button, which would execute the injected scripts in the context of the victim's browser session.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's session, potentially leading to unauthorized actions or data exposure.

Remediation

Users should upgrade to n8n version 2.8.0 or 2.6.4 and later. If an immediate upgrade is not possible, consider limiting credential creation and sharing permissions to trusted users and restricting access to the n8n instance to trusted users only.

Added: Jul 8, 2026, 2:35 PM
Updated: Jul 8, 2026, 2:35 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.7
exploitability
4.4
remediation
7.9
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.