CVE-2026-54303: medium-severity vulnerability in n8n-io n8n
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
n8n versions before 2.24.0 have a security flaw where Facebook, WhatsApp, and Microsoft Teams webhook endpoints reflect user input directly into web pages without proper protection, allowing attackers to inject malicious scripts that execute in a logged-in user's browser.
A reflected XSS vulnerability exists in Meta and Microsoft Teams trigger node endpoints where unsanitized query parameters are echoed into HTTP responses without Content-Security-Policy protections. An attacker can craft a malicious URL and trick a logged-in n8n user into visiting it, causing arbitrary JavaScript execution in the context of the n8n application.
In the same product, most dangerous first.