All verified exploits

CVE-2026-42235 MCP OAuth Client Name Stored XSS

Deterministic critical n8n Added cve-verified-cve-2026-42235

Detects n8n instances vulnerable to stored XSS via MCP OAuth client registration. An unauthenticated attacker can register an MCP OAuth client whose crafted client_name bypasses the sanitizeHtml() href filter — the URL-validation regex used the multiline flag (/^https?:\/\//gm), so payloads like 'javascript:alert(1);//\nhttps://x.com' slip through and become a clickable javascript: link in the OAuth consent / revocation toast. A single click in an authenticated victim's session executes arbitrary JavaScript, enabling credential theft, workflow manipulation, and privilege escalation. Versions <1.123.32, 2.17.0-2.17.3, and 2.18.0 affected. Update to 1.123.32, 2.17.4, or 2.18.1.

Is your app exploitable through CVE-2026-42235?

Scan your domain free