n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-form-trigger-node | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
26 Jun 2026, 02:02
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-form-trigger-node - Third Party Advisory | |
| First Time |
N8n
N8n n8n |
|
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
24 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 13:16
Updated : 2026-06-26 02:02
NVD link : CVE-2026-56358
Mitre link : CVE-2026-56358
CVE.ORG link : CVE-2026-56358
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
