logo

Same Origin, Same Tricks: Bypassing n8n’s CSP Sandbox (CVE-2026-27578)

ID: 34b3ed4a-4b56-5e3a-92dc-9ec1d5601a76

STIX ID: report--34b3ed4a-4b56-5e3a-92dc-9ec1d5601a76

Feed Name: Checkmarx Zero

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-27

Author: Ori Ron

...
...

Checkmarx Zero disclosed CVE-2026-27578: a stored XSS in n8n’s “Respond to Webhook” node that bypasses the platform’s CSP sandbox by returning SVG content (image/svg+xml), enabling arbitrary JavaScript execution in authenticated users’ sessions and risking session hijacking and account takeover; affected versions are listed and fixes are available in n8n 2.10.1, 2.9.3, and 1.123.22 — administrators should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.