CVE-2026-54301: stato di sfruttamento e disponibilità della patch

CVE-2026-54301 · CVSS 5.4 MEDIUM · EPSS <1%

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The binary response path bypassed the central Content-Security-Policy sandbox header, allowing a public webhook to execute JavaScript in the n8n origin when visited by an authenticated user, with access to that user's session. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.

CVE-2026-54301 viene sfruttato?

Quali prodotti e versioni sono interessati?

Nessun elenco di pacchetti interessati registrato qui.

Esiste una patch?

Nessun identificativo di patch registrato qui.

Cosa ha pubblicato PlainSec su CVE-2026-54301

Fonti primarie

Cosa questa scheda non dice

KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-08-11.