Количество 2
Количество 2
CVE-2026-56358
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
GHSA-q4fm-pjq6-m63g
n8n has a Stored XSS Vulnerability in its Form Trigger
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56358 n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-q4fm-pjq6-m63g n8n has a Stored XSS Vulnerability in its Form Trigger | CVSS3: 5.4 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу