<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T14:14:23.147615+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339484</id>
    <title>EUVD-2026-339484</title>
    <updated>2026-10-05T14:14:23.149832+00:00</updated>
    <content>EUVD-2026-339484</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65597</id>
    <title>fkie_cve-2026-65597</title>
    <updated>2026-10-05T14:14:23.149862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call authenticated APIs using the victim's session. An account with global:member privileges can exploit the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-65597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p3rg-hrf9-w9gj</id>
    <title>GHSA-p3rg-hrf9-w9gj — n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview</title>
    <updated>2026-10-05T14:14:23.149894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: n8n</p>
<p>## Impact</p>
<p>The HTML preview renders execution output into an `iframe srcdoc` without `sandbox`, so a sanitizer bypass lets injected script run same-origin as the editor. When a victim opens the preview, it can call authenticated APIs with their session. An account with `global:member` privileges can exploit it.</p>
<p>## Patches</p>
<p>The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability.</p>
<p>## Workarounds</p>
<p>If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
- Restrict n8n instance access to fully trusted users only.
- Set the `N8N_CONTENT_SECURITY_POLICY` environment variable to a policy that blocks inline scripts.
- Avoid exposing workflows that render externally-controlled input into the HTML node or binary HTML preview to untrusted users.</p>
<p>These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p3rg-hrf9-w9gj"/>
  </entry>
</feed>
