What is CVE-2026-65597?
A DOM-based Cross-Site Scripting vulnerability exists in the HTML preview feature of n8n. The execution output is rendered into an iframe srcdoc without a sandbox attribute, allowing a sanitizer bypass to execute scripts in the same-origin context as the editor. Affected users should upgrade to versions 1.123.64, 2.29.8, 2.30.1, or later.
Azərbaycanca: n8n platformasının HTML önbaxış funksiyasında DOM əsaslı Cross-Site Scripting (XSS) zəifliyi aşkar edilib. İframe 'sandbox' atributu olmadığı üçün sanitayzerdən yan keçən skript redaktorla eyni mənşəli kontekstdə icra oluna bilər. İstifadəçilərə təsirə məruz qalan versiyalardan 1.123.64, 2.29.8 və ya 2.30.1 və daha yuxarı versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: n8n
FAQ2
What type of security vulnerability was discovered in the HTML preview feature of n8n?
A DOM-based Cross-Site Scripting (XSS) vulnerability was discovered in the HTML preview feature. This vulnerability allows a sanitizer bypass because the iframe lacks a `sandbox` attribute.
Which n8n versions are recommended for upgrading to protect against CVE-2026-65597?
Users are recommended to upgrade to versions 1.123.64, 2.29.8, 2.30.1, or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.