All verified exploits

CVE-2026-33749 Binary Data Stored XSS

Deterministic critical n8n Added cve-verified-cve-2026-33749

Detects n8n instances where the /rest/binary-data endpoint serves HTML inline without Content-Security-Policy sandbox when binary data has no filename. An authenticated user can craft a workflow that executes JavaScript in other users' browsers on the n8n origin, stealing credentials and hijacking sessions. Versions <1.123.27, <2.13.3, and 2.14.0 affected.

Is your app exploitable through CVE-2026-33749?

Scan your domain free