Home

Description

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.

PUBLISHED Reserved 2026-06-20 | Published 2026-06-24 | Updated 2026-06-24 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

Any version before 1.123.25
affected

1.123.25 (semver)
unaffected

2.0.0-rc.0 (semver) before 2.11.2
affected

2.11.2 (semver)
unaffected

Default status
unaffected

Any version before 2.11.2
affected

2.11.2 (semver)
unaffected

Default status
unaffected

Any version before 1.123.25
affected

1.123.25 (semver)
unaffected

Credits

tr4ce-ju reporter

References

github.com/...io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g (GitHub Security Advisory (GHSA-q4fm-pjq6-m63g)) vendor-advisory

www.vulncheck.com/...oss-site-scripting-in-form-trigger-node (VulnCheck Advisory: n8n - Stored Cross-Site Scripting in Form Trigger Node) third-party-advisory

cve.org (CVE-2026-56358)

nvd.nist.gov (CVE-2026-56358)

Download JSON