CVE-2026-56358

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

26 Jun 2026, 02:02

Type Values Removed Values Added
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g - () https://github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-form-trigger-node - () https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-form-trigger-node - Third Party Advisory
First Time N8n
N8n n8n
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

24 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 13:16

Updated : 2026-06-26 02:02


NVD link : CVE-2026-56358

Mitre link : CVE-2026-56358

CVE.ORG link : CVE-2026-56358


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')