Executive brief
n8n is a popular workflow automation tool that allows users to connect different apps and services. A security flaw in its Form Trigger component allows an authorized user to inject malicious scripts into published forms. If exploited, this could allow an attacker to hijack form submissions or conduct phishing attacks against anyone visiting the form.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in n8n's Form Trigger node due to insufficient sanitization of CSS input. An authenticated attacker with permissions to create or modify workflows can inject a malicious payload that is stored and subsequently executed in the browser of any user visiting the published form. While the existing Content Security Policy (CSP) mitigates the risk of session cookie theft, it does not prevent script execution or manipulation of form actions. The issue is fixed in versions 2.12.0, 2.11.2, and 1.123.25.
Affected products
- n8n-io n8n >= 2.0.0-rc.0, < 2.11.2; < 1.123.25
Timeline
- 2026-03-25: disclosed
- 2026-03-27: advisory