logo

N8N: Shared Credentials and Account Takeover

ID: 4df920bb-1d2d-509f-a8e8-b0685a7de709

STIX ID: report--4df920bb-1d2d-509f-a8e8-b0685a7de709

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Yohann Sillam

...
...

A stored XSS vulnerability was discovered in n8n's OAuth "Authorization URL" handling that allows attackers to inject JavaScript into shared credentials; when a victim clicks "Connect my account" the payload executes in their session, enabling account takeover, credential exfiltration, and potential full instance takeover. The issue was disclosed on Jan 29 and fixed in n8n v2.6.4.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.