n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-3c7f-5hgj-h279 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-chat-trigger-node-custom-css-field | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Jul 2026, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:n8n:n8n:2.14.0:*:*:*:*:node.js:*:* cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-3c7f-5hgj-h279 - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-chat-trigger-node-custom-css-field - Third Party Advisory | |
| First Time |
N8n
N8n n8n |
30 Jun 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 23:17
Updated : 2026-07-02 19:38
NVD link : CVE-2026-56356
Mitre link : CVE-2026-56356
CVE.ORG link : CVE-2026-56356
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
