GHSA-9wcp-9r3j-383q: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
Summary
n8n (a workflow automation tool) has a stored DOM XSS vulnerability (DOM XSS is when malicious code runs in a user's browser after being stored in an application) in its Resource Locator feature. An attacker can craft a workflow with a malicious `cachedResultUrl` parameter that executes JavaScript when a victim opens the workflow and interacts with external links.
Solution / Mitigation
The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later. If upgrading is not immediately possible, administrators can restrict workflow creation and editing permissions to fully trusted users only, or audit existing workflows for unexpected `cachedResultUrl` values containing non-HTTP(S) schemes. However, these workarounds do not fully remediate the risk and should only be used as short-term measures.
Vulnerability Details
EPSS: 0.0%
Yes
July 22, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-9wcp-9r3j-383q
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%