CVE-2026-27578 | n8n-io n8n up to 1.123.21/2.9.2/2.10.0 Environment Variable NODES_EXCLUDE cross site scripting (GHSA-2p9h-rqjw-gm92)
A vulnerability marked as problematic has been reported in n8n-io n8n up to 1.123.21/2.9.2/2.10.0. This vulnerability affects unknown code of the component Environment Variable Handler. This manipulation of the argument NODES_EXCLUDE causes basic cross site scripting.
This vulnerability is handled as CVE-2026-27578. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.