CVE-2026-65592
## Impact The Resource Locator passes the workflow-persisted `cachedResultUrl` to `window.open()` without scheme validation. When a victim opens the crafted workflow and interact with external links, the JavaScript payload runs in the victim's browser. ## Patches The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict workflow creation and editing permissions to fully trusted users only. - Audit existing workflows for unexpected `cachedResultUrl` values containing non-HTTP(S) schemes. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Properties
- ghsa_id
- GHSA-9wcp-9r3j-383q
- severity
- high
- summary
- n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
- epss_score
- 0.00172
- cve_id
- CVE-2026-65592
- is_ghsa_only
- false
- ghsa_published
- 2026-07-22T17:59:07Z
- source_url
- https://github.com/advisories/GHSA-9wcp-9r3j-383q
- epss_percentile
- 0.06742
- ghsa_updated
- 2026-07-22T17:59:08Z
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph