Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56359

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия до 2.6.4 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия от 2.7.0 (включая) до 2.8.0 (исключая)

EPSS

Процентиль: 4%
0.00141
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
2 месяца назад

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges.

EPSS

Процентиль: 4%
0.00141
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79