Medium severity5.4NVD Advisory· Published Jun 24, 2026· Updated Jun 26, 2026
CVE-2026-56358
CVE-2026-56358
Description
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
n8nnpm | >= 2.0.0-rc.0, < 2.11.2 | 2.11.2 |
n8nnpm | < 1.123.25 | 1.123.25 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-q4fm-pjq6-m63gghsaADVISORY
- github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63gnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-56358ghsaADVISORY
- www.vulncheck.com/advisories/n8n-stored-cross-site-scripting-in-form-trigger-nodenvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.