CVE-2026-65597
## Impact The HTML preview renders execution output into an `iframe srcdoc` without `sandbox`, so a sanitizer bypass lets injected script run same-origin as the editor. When a victim opens the preview, it can call authenticated APIs with their session. An account with `global:member` privileges can exploit it. ## Patches The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Set the `N8N_CONTENT_SECURITY_POLICY` environment variable to a policy that blocks inline scripts. - Avoid exposing workflows that render externally-controlled input into the HTML node or binary HTML preview to untrusted users. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Properties
- ghsa_id
- GHSA-p3rg-hrf9-w9gj
- severity
- high
- summary
- n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
- epss_score
- 0.00214
- cve_id
- CVE-2026-65597
- is_ghsa_only
- false
- ghsa_published
- 2026-07-22T17:57:14Z
- source_url
- https://github.com/advisories/GHSA-p3rg-hrf9-w9gj
- epss_percentile
- 0.11651
- ghsa_updated
- 2026-07-22T17:58:39Z
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph