CVE-2026-56358 Details
Description
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
A stored cross-site scripting vulnerability has been identified in n8n versions prior to 1.123.25 (1.x) and prior to 2.11.2 (2.x), with the fix also included in n8n 2.12.0. The vulnerability arises in the Form Trigger node's CSS sanitization, allowing authenticated users with workflow creation permissions to inject malicious scripts. These injected scripts execute persistently for all visitors of the form, enabling form hijacking and phishing attacks.
Users should upgrade to n8n versions 2.12.0, 2.11.2, or 1.123.25. If an immediate upgrade is not possible, consider limiting workflow creation and editing permissions to trusted users or disabling the Form Trigger node by adding 'n8n-nodes-base.formTrigger' to the 'NODES_EXCLUDE' environment variable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-form-trigger-node | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.25 >= 2.0.0, < 2.11.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |