CVE-2026-56354 Details
Description
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions can inject malicious scripts or redirect parameters to perform stored XSS attacks or phishing redirects against end users.
A cross-site scripting (XSS) and open redirect vulnerability has been identified in n8n versions prior to 1.123.24, 2.10.4, and 2.12.0, across both the 1.x and 2.x branches. The issue arises in the Form Node, where unsanitized HTML in description fields and lax iframe sandbox policies create vulnerabilities. Authenticated users with the ability to create workflows can exploit this by injecting malicious scripts or redirect parameters, leading to stored XSS attacks or phishing redirects for end users.
Users should upgrade to n8n versions 1.123.24, 2.10.4, or 2.12.0. If an immediate upgrade is not possible, consider limiting workflow creation and editing permissions to trusted users, or temporarily disabling the Form Node or Form Trigger Node by adding them to the NODES_EXCLUDE environment variable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-w673-8fjw-457c | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/n8n-cross-site-scripting-and-open-redirect-in-form-node | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.24 >= 2.0.0, < 2.10.4 >= 2.10.0, < 2.10.4 >= 2.11.0, < 2.12.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |