Junglewise Threat Intelligence

CVE-2026-56358: n8n stored XSS in Form Trigger node

CVE-2026-56358 · Severity: medium · CVSS 5.4 · Published 2026-06-24

Technologies: N8n-Io N8n. Vendors: N8n.

Executive brief

n8n is a popular workflow automation tool that allows users to connect different apps and services. A security flaw in its Form Trigger component allows an authorized user to inject malicious scripts into published forms. If exploited, this could allow an attacker to hijack form submissions or conduct phishing attacks against anyone visiting the form.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in n8n's Form Trigger node due to insufficient sanitization of CSS input. An authenticated attacker with permissions to create or modify workflows can inject a malicious payload that is stored and subsequently executed in the browser of any user visiting the published form. While the existing Content Security Policy (CSP) mitigates the risk of session cookie theft, it does not prevent script execution or manipulation of form actions. The issue is fixed in versions 2.12.0, 2.11.2, and 1.123.25.

Affected products

  • n8n-io n8n >= 2.0.0-rc.0, < 2.11.2; < 1.123.25

Timeline

  • 2026-03-25: disclosed
  • 2026-03-27: advisory

References

Related threats