GHSA-h5xr-fqvj-253p: Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
Summary
n8n (a workflow automation tool) before versions 1.123.64, 2.29.8, and 2.30.1 had a stored DOM XSS vulnerability (a type of attack where malicious code is saved and then runs in a user's browser when they view a page). An attacker with workflow creation privileges could inject malicious code into a parameter called cachedResultUrl that gets passed to window.open() without proper validation, allowing the code to execute when a victim opens the workflow.
Solution / Mitigation
Update n8n to version 1.123.64, 2.29.8, or 2.30.1 or later.
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://github.com/advisories/GHSA-h5xr-fqvj-253p
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 72%