MEDIUM

CVE-2026-56358

N8n N8n 2026-06-24 CVSS v3.1
CVSS
5.4

Description

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.

Summary dbcve.org

A stored cross-site scripting vulnerability in n8n's Form Trigger node allows authenticated users with workflow creation permissions to inject malicious scripts through improper CSS sanitization, which executes persistently for all form visitors.

Mitigation

Upgrade n8n to version 1.123.25 (1.x series), 2.11.2 (2.x series), or 2.12.0 and later to patch the CSS sanitization in the Form Trigger node.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.24%
Probability of exploitation in next 30 days
15.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE