CVE-2026-42235: falha de alta gravidade em n8n-io n8n
n8n: XSS via MCP OAuth client
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.8epss 0.5%
probabilidade de exploração
0.5%top 59% das CVEs
exploração observada
nãonenhuma fonte reporta
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that access, a toast notification would render the injected script. Clicking the link would execute arbitrary JavaScript in the victim's authenticated n8n browser session, enabling credential and session token theft, workflow manipulation, or privilege escalation. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Produtos afetados
n8n-io · n8nCVEs relacionadas — n8n-io n8n
No mesmo produto, das mais perigosas para as menos.
CVE-2025-68613CRITICALn8n Vulnerable to Remote Code Execution via Expression InjectionEPSS 99.0%KEVCVE-2026-21858CRITICALn8n Vulnerable to Unauthenticated File Access via Improper Webhook Request HandlingEPSS 78.2%CVE-2025-68668CRITICALn8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code NodeEPSS 13.2%CVE-2026-21877CRITICALn8n is vulnerable to Remote Code Execution via Arbitrary File WriteEPSS 5.4%CVE-2026-25055HIGHn8n Arbitrary File Write on Remote Systems via SSH NodeEPSS 1.9%CVE-2026-25049CRITICALn8n Has an Expression Escape Vulnerability Leading to RCEEPSS 1.6%