CVE-2026-56358
Description
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
Summary dbcve.org
A stored cross-site scripting vulnerability in n8n's Form Trigger node allows authenticated users with workflow creation permissions to inject malicious scripts through improper CSS sanitization, which executes persistently for all form visitors.
Mitigation
Upgrade n8n to version 1.123.25 (1.x series), 2.11.2 (2.x series), or 2.12.0 and later to patch the CSS sanitization in the Form Trigger node.