
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33749 is a stored Cross-Site Scripting (XSS) vulnerability in n8n, an open-source workflow automation platform, titled "XSS via Binary Data Inline HTML Rendering." An authenticated user with workflow creation or modification permissions can craft a workflow that generates an HTML binary data object without a filename; the /rest/binary-data endpoint then serves this content inline on the n8n origin without Content-Disposition or Content-Security-Policy headers, enabling arbitrary JavaScript execution in a victim's browser. The vulnerability was published on March 25, 2026, and affects all n8n versions prior to 1.123.27, versions 2.0.0 through 2.13.2, and version 2.14.0. It carries a CVSS v3.1 base score of 9.0 (High) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Github Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The /rest/binary-data endpoint fails to set Content-Disposition: attachment or a restrictive Content-Security-Policy header when serving binary data objects, allowing HTML content to render inline in the browser on the n8n origin. An attacker crafts a workflow node that outputs an HTML payload as a binary data object with no filename, then retrieves the resulting binary data URL and sends it to a higher-privileged user (e.g., an admin). When the victim opens the URL while authenticated, the HTML renders with full same-origin JavaScript access to the n8n session (GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript within the authenticated session of a higher-privileged user, including administrators. This enables exfiltration of stored workflows and credentials (such as API keys and service account tokens configured in n8n), unauthorized modification of workflows, and privilege escalation to admin-level access. Because n8n workflows often integrate with external services and APIs, credential theft could facilitate lateral movement into connected systems (GitHub Advisory, Github Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038% (0.000380), placing it in the 16th percentile for exploitation probability within 30 days. Exploitation requires the attacker to already be an authenticated user with workflow creation/modification permissions and requires social engineering to trick a higher-privileged user into clicking a malicious binary data URL.
/rest/binary-data/<id> URL from the n8n instance./rest/binary-data/<id> endpoints from admin or high-privileged user sessions, especially originating from unexpected IP addresses or user agents; outbound requests from the n8n server to external endpoints shortly after a binary data URL is accessed./rest/binary-data/ URL; API calls to credential listing or user management endpoints (e.g., /rest/credentials, /rest/users) immediately after binary data access.Upgrade n8n to one of the patched versions: 1.123.27 (1.x branch), 2.13.3 (2.x branch), or 2.14.1 (2.14.x branch). If immediate upgrading is not possible, administrators should restrict workflow creation and editing permissions to fully trusted users only, and limit network access to the n8n instance to prevent untrusted users from accessing binary data URLs. Note that these workarounds do not fully remediate the risk and are intended only as short-term measures until patching is completed (GitHub Advisory).
The vulnerability was reported by security researcher simonkoeck and published by the n8n security team (Jubke) on March 25, 2026, via GitHub's security advisory system. The advisory was noted on Bluesky and aggregated by several vulnerability tracking services shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."