CVE-2026-54303: n8n

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflected XSS in the n8n origin when a logged-in user visits a crafted URL. This vulnerability is fixed in 2.24.0.

Affected products

  • n8n n8n: before 2.24.0 (fixed in 2.24.0)

Published 2026-06-23. Last modified 2026-06-25.