js · n8nHeads-up
n8n Reflected XSS in Meta and Microsoft Teams Trigger Nodes
Reflected XSS vulnerability in Meta and Microsoft Teams trigger nodes due to unsanitized query parameter reflection in HTTP response.
What changed
Reflected XSS vulnerability in Meta and Microsoft Teams trigger nodes due to unsanitized query parameter reflection in HTTP response.
Who it affects
Users of n8n versions prior to 2.24.0 who use Facebook or Microsoft Teams trigger nodes.
What to do today
Upgrade to n8n version 2.24.0 or later, or apply workarounds: limit workflow creation permissions and exclude affected nodes via NODES_EXCLUDE.
The trail
Collected→
Audited→
Written→
Published
Source
GitHub Advisory · n8n