Executive brief
n8n is a workflow automation tool used to connect different software services. A security vulnerability in its Form Node component allows users with workflow creation permissions to inject malicious scripts or set up deceptive redirects. This could be used to target other users with phishing attacks or to execute unauthorized actions in their browsers when they visit a compromised form.
Technical details
n8n is vulnerable to stored cross-site scripting (XSS) and open redirects within its Form Node component. The root cause is a failure to sanitize HTML input in description fields and the use of overly permissive iframe sandbox policies. An authenticated attacker with privileges to create or modify workflows can inject malicious payloads into these fields. When an end user interacts with the resulting form, the script executes in their browser context or they are redirected to an arbitrary external URL. The issue is fixed in versions 1.123.24, 2.10.4, and 2.12.0.
Affected products
- n8n n8n < 1.123.24, 2.0.0-rc.0 to < 2.10.4, 2.11.0 to < 2.12.0
Timeline
- 2026-03-25: advisory: GitHub Security Advisory published
- 2026-07-10: disclosed: NVD publication date