Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-56358

3 месяца назад

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-q4fm-pjq6-m63g

6 месяцев назад

n8n has a Stored XSS Vulnerability in its Form Trigger

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56358

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-q4fm-pjq6-m63g

n8n has a Stored XSS Vulnerability in its Form Trigger

CVSS3: 5.4
0%
Низкий
6 месяцев назад

Уязвимостей на страницу