Intel

AIKIDO-2025-10390

n8n-nodes-base is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 20, 2025

45

Medium Risk

This Affects:

JSn8n-nodes-base
1.90.0 - 1.90.0
0.0.1 - 1.98.1
Fixed in 1.98.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) when rendering FormNode components due to insufficient sanitization of the video and iframe tags. This allows attackers to inject and execute malicious scripts in the affected application.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n-nodes-base is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.98.1 and 1.90.0 - 1.90.0.

How to fix this

Upgrade the n8n-nodes-base library to the patch version.