CVE-2026-56354: n8n - Cross-Site Scripting and Open Redirect in Form Node
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions can inject malicious scripts or redirect parameters to perform stored XSS attacks or phishing redirects against end users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56354?
The severity of CVE-2026-56354 is rated medium, with a CVSS score of 5.1.
How does CVE-2026-56354 affect n8n?
CVE-2026-56354 affects n8n by allowing cross-site scripting and open redirect vulnerabilities in the Form Node, which can be exploited by authenticated users.
How do I fix CVE-2026-56354?
To fix CVE-2026-56354, upgrade n8n to versions 1.123.24, 2.10.4, or 2.12.0 or later.
What types of attacks can CVE-2026-56354 enable?
CVE-2026-56354 can enable cross-site scripting attacks and allow unauthorized redirections via unsanitized HTML fields.
Who is affected by CVE-2026-56354?
Authenticated users with workflow creation permissions in n8n are affected by CVE-2026-56354.