Cross-site scripting in n8n - #VU127209
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the Chat Trigger node Custom CSS field when rendering the public chat page. A remote user can inject malicious JavaScript into the Custom CSS field to execute arbitrary script in a victim's browser.
User interaction is required, as a victim must visit the chat URL.