PatchSiren cyber security CVE debrief
CVE-2026-56359 n8n CVE debrief
CVE-2026-56359 is a cross-site scripting vulnerability in n8n before 2.8.0. Authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges. This vulnerability can have a significant impact on the security of n8n instances, and users should take steps to mitigate it.
- Vendor
- n8n
- Product
- Unknown
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-08
- Original CVE updated
- 2026-07-09
- Advisory published
- 2026-07-08
- Advisory updated
- 2026-07-09
Who should care
Users of n8n versions before 2.8.0 should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to version 2.8.0 or later and being cautious when clicking on OAuth authorization buttons. Additionally, security teams and vulnerability management teams should review the affected scope and severity of this vulnerability and plan accordingly.
Technical summary
The vulnerability exists in the credential management flow of n8n, specifically in the OAuth2 credential Authorization URL fields. Authenticated users can inject malicious JavaScript URLs, which can be used by attackers to execute arbitrary scripts in the victim's browser session. This vulnerability can be mitigated by upgrading to n8n version 2.8.0 or later and being cautious when clicking on OAuth authorization buttons.
Defensive priority
Medium
Recommended defensive actions
- Upgrade to n8n version 2.8.0 or later
- Be cautious when clicking on OAuth authorization buttons
- Monitor for suspicious activity in n8n instances
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-08T14:17:16.620Z and was last modified on 2026-07-09T15:16:38.060Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus and may not reflect the full scope of the vulnerability. Defenders should verify the affected scope and severity with the official CVE record and NVD entry. The vulnerability exists in n8n before 2.8.0, and users should exercise caution when using OAuth2 credential Authorization URL fields.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56359 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56359
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56359 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56359
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/security/advisories/GHSA-364x-8g5j-x2pr
[email protected] - Mitigation, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/n8n-cross-site-scripting-in-credential-management-oauth2-authorization-url
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.