n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions can inject malicious scripts or redirect parameters to perform stored XSS attacks or phishing redirects against end users.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-w673-8fjw-457c | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-cross-site-scripting-and-open-redirect-in-form-node | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 16:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
N8n
N8n n8n |
|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-w673-8fjw-457c - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-cross-site-scripting-and-open-redirect-in-form-node - Third Party Advisory | |
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:* |
10 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 15:16
Updated : 2026-07-13 16:54
NVD link : CVE-2026-56354
Mitre link : CVE-2026-56354
CVE.ORG link : CVE-2026-56354
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
