CVE-2026-33749: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33749 is a stored Cross-Site Scripting (XSS) vulnerability in n8n, an open-source workflow automation platform, titled "XSS via Binary Data Inline HTML Rendering." An authenticated user with workflow creation or modification permissions can craft a workflow that generates an HTML binary data object without a filename; the /rest/binary-data endpoint then serves this content inline on the n8n origin without Content-Disposition or Content-Security-Policy headers, enabling arbitrary JavaScript execution in a victim's browser. The vulnerability was published on March 25, 2026, and affects all n8n versions prior to 1.123.27, versions 2.0.0 through 2.13.2, and version 2.14.0. It carries a CVSS v3.1 base score of 9.0 (High) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Github Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The /rest/binary-data endpoint fails to set Content-Disposition: attachment or a restrictive Content-Security-Policy header when serving binary data objects, allowing HTML content to render inline in the browser on the n8n origin. An attacker crafts a workflow node that outputs an HTML payload as a binary data object with no filename, then retrieves the resulting binary data URL and sends it to a higher-privileged user (e.g., an admin). When the victim opens the URL while authenticated, the HTML renders with full same-origin JavaScript access to the n8n session (GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript within the authenticated session of a higher-privileged user, including administrators. This enables exfiltration of stored workflows and credentials (such as API keys and service account tokens configured in n8n), unauthorized modification of workflows, and privilege escalation to admin-level access. Because n8n workflows often integrate with external services and APIs, credential theft could facilitate lateral movement into connected systems (GitHub Advisory, Github Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038% (0.000380), placing it in the 16th percentile for exploitation probability within 30 days. Exploitation requires the attacker to already be an authenticated user with workflow creation/modification permissions and requires social engineering to trick a higher-privileged user into clicking a malicious binary data URL.

Exploitation steps

  1. Gain authenticated access: Obtain credentials for an n8n account with workflow creation or modification permissions (e.g., a low-privileged user account).
  2. Craft a malicious workflow: Create or modify a workflow that includes a node (e.g., a Function/Code node) that outputs an HTML payload as a binary data object without a filename. The HTML payload should contain a JavaScript snippet designed to exfiltrate session data, credentials, or perform admin actions via the n8n API.
  3. Execute the workflow: Run the workflow to generate the binary data object and obtain the resulting /rest/binary-data/<id> URL from the n8n instance.
  4. Deliver the malicious URL: Send the binary data URL to a higher-privileged user (e.g., an admin) via internal messaging, email, or another communication channel, using social engineering to entice them to click the link while authenticated to n8n.
  5. Achieve JavaScript execution: When the victim opens the URL in their browser, the HTML renders inline on the n8n origin without CSP or Content-Disposition restrictions, executing the attacker's JavaScript in the victim's authenticated session.
  6. Exfiltrate or escalate: The injected script can call n8n's REST API endpoints (e.g., to list credentials, export workflows, or promote the attacker's account to admin) using the victim's session cookies or tokens (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /rest/binary-data/<id> endpoints from admin or high-privileged user sessions, especially originating from unexpected IP addresses or user agents; outbound requests from the n8n server to external endpoints shortly after a binary data URL is accessed.
  • Logs: n8n access logs showing a low-privileged user creating or modifying workflows followed shortly by a high-privileged user accessing a /rest/binary-data/ URL; API calls to credential listing or user management endpoints (e.g., /rest/credentials, /rest/users) immediately after binary data access.
  • Application: Unexpected changes to workflow definitions, newly created admin accounts, or modified user roles in the n8n database; credentials being accessed or exported without a corresponding legitimate user action.

Mitigation and workarounds

Upgrade n8n to one of the patched versions: 1.123.27 (1.x branch), 2.13.3 (2.x branch), or 2.14.1 (2.14.x branch). If immediate upgrading is not possible, administrators should restrict workflow creation and editing permissions to fully trusted users only, and limit network access to the n8n instance to prevent untrusted users from accessing binary data URLs. Note that these workarounds do not fully remediate the risk and are intended only as short-term measures until patching is completed (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher simonkoeck and published by the n8n security team (Jubke) on March 25, 2026, via GitHub's security advisory system. The advisory was noted on Bluesky and aggregated by several vulnerability tracking services shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management