CVE-2026-54301: high-severity vulnerability in n8n-io n8n
n8n: Same-Origin XSS in Respond to Webhook Node
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The binary response path bypassed the central Content-Security-Policy sandbox header, allowing a public webhook to execute JavaScript in the n8n origin when visited by an authenticated user, with access to that user's session. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
n8n-io · n8nRelated CVEs — n8n-io n8n
In the same product, most dangerous first.
CVE-2025-68613CRITICALn8n Vulnerable to Remote Code Execution via Expression InjectionEPSS 99.0%KEVCVE-2026-21858CRITICALn8n Vulnerable to Unauthenticated File Access via Improper Webhook Request HandlingEPSS 78.2%CVE-2025-68668CRITICALn8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code NodeEPSS 13.2%CVE-2026-21877CRITICALn8n is vulnerable to Remote Code Execution via Arbitrary File WriteEPSS 5.4%CVE-2026-25055HIGHn8n Arbitrary File Write on Remote Systems via SSH NodeEPSS 1.9%CVE-2026-25049CRITICALn8n Has an Expression Escape Vulnerability Leading to RCEEPSS 1.6%