---
cve: "CVE-2026-77075"
severity: "HIGH"
cvss: 8.4
epss: "0.5%"
vendor: "n8n-io"
kev: false
exploited: false
published: "2026-08-20 12:16:38"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-08T01:21:57+02:00"
---

# CVE-2026-77075

> 8.4 HIGH · 🧪 PoC

## Beschreibung

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored value directly into the node type's URL template without checking for expression syntax. An authenticated member can store a malicious value so that when another user opens the affected node in the editor, the injected expression is evaluated as JavaScript in the victim's authenticated session (cross-user script execution).

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |

## Patch verfügbar (OSV)

- 430e6e597ab43d2326aa11cd30fcf633766fca31 (Commit)
- 14c9aef0552fb4776501ca1c4589451891dd0ef4 (Commit)

## BSI-Hinweise (deutsch)

- [n8n: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-2681) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in n8n ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Cross-Site-Scripting oder Server-Side Request Forgery durchzuführen oder einen Denial-of-Service-Zustand herbeizuführen.

## Referenzen

- <https://github.com/n8n-io/n8n/security/advisories/GHSA-fh4c-9rr2-p7qc>
- <https://www.vulncheck.com/advisories/n8n-before-expression-injection-via-resource-locator>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-77075/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
