GHSA-vhcw-f978-xjjg: Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
highvulnerability
security
Source: GitHub Advisory DatabaseJuly 22, 2026
Summary
n8n (a workflow automation tool) had a DOM-based XSS vulnerability (a type of security flaw where malicious code runs in a user's browser) in its HTML preview feature. The preview rendered output into an iframe (an embedded browser window) without proper security restrictions, allowing an attacker with basic member privileges to inject malicious script that could steal the victim's session and make unauthorized API calls when the victim opens the preview.
Classification
Attack SophisticationModerate
Affected Vendors
Affected Packages
n8n@< 1.123.64
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-vhcw-f978-xjjg
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%