Cross-site scripting in n8n - #VU128723
Published: April 30, 2026
Vulnerability details
The vulnerability allows a remote user to perform stored cross-site scripting.
The vulnerability exists due to improper neutralization of input during web page generation in the Form Node description field when rendering form content. A remote user can configure a form node with a crafted HTML description to perform stored cross-site scripting.
User interaction is required when an end user visits the form.