← Back to Research Blog
CRITICAL CVE-2026-54309

Critical Remote Code Execution Vulnerability in n8n Exposes Browser Sessions to Unauthenticated Attackers

10.0
CRITICAL
ai browser bridge, mcp-browser, n8n
2026-08-11

Overview

CVE-2026-54309, a critical unauthenticated remote code execution flaw in n8n, enables attackers to hijack browser sessions, execute arbitrary JavaScript, and steal sensitive data. With a CVSS score of 10.0, this vulnerability affects widely adopted workflow automation platforms when configured in HTTP transport mode.


Technical Analysis

The vulnerability stems from the @n8n/mcp-browser module's HTTP transport endpoint, which lacks authentication for session initialization and tool invocation. Attackers can exploit this by sending crafted HTTP requests to establish sessions and invoke browser-control tools. This allows navigation, cookie theft, and arbitrary code execution in connected browsers, particularly when the AI Browser Bridge extension is active. Exploitation requires network reachability of the MCP endpoint.

Enterprise & DIB Impact

Defense Industrial Base (DIB) and enterprise environments leveraging n8n for automation face severe risks, including unauthenticated access to internal systems, credential theft, and browser-based supply chain attacks. Malicious websites or compromised internal services could exploit this flaw to pivot into sensitive networks.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512