SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-77075

HIGH · CVSS 7.3 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects n8n versions prior to 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1, allowing authenticated users to inject malicious JavaScript into the resource-locator field, which is then executed in the context of another user's session. This expression injection could lead to cross-user script execution, potentially compromising user data and session integrity. Organizations using affected versions of n8n should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77075
Severity
HIGH
CVSS
7.3
EPSS
0.26%
Java

Original NVD Description

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored value directly into the node type's URL template without checking for expression syntax. An authenticated member can store a malicious value so that when another user opens the affected node in the editor, the injected expression is evaluated as JavaScript in the victim's authenticated session (cross-user script execution).

Related CVEs

Other vulnerabilities affecting the same vendor(s)