CVE-2026-33749 is a critical Cross-Site Scripting (XSS) vulnerability affecting n8n, an open-source workflow automation platform, in versions prior to 1.123.27, 2.13.3, and 2.14.1. Rated 9.0 Critical, it allows an authenticated attacker with workflow creation/modification permissions to craft a malicious workflow that, when its URL is accessed by a higher-privileged user, executes arbitrary JavaScript. This enables exfiltration of sensitive data, modification of workflows, or privilege escalation to administrator roles. There is currently no evidence of active exploitation, nor is public exploit code available, though the vulnerability has garnered limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.123.27CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.13.3CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
2.14.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:2.14.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.