CVE-2026-54303: n8n
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflected XSS in the n8n origin when a logged-in user visits a crafted URL. This vulnerability is fixed in 2.24.0.
Affected products
- n8n n8n: before 2.24.0 (fixed in 2.24.0)
Published 2026-06-23. Last modified 2026-06-25.