Cross-site scripting in n8n - #VU153006

 

Cross-site scripting in n8n - #VU153006

Published: September 30, 2026


Vulnerability identifier: #VU153006
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute script in visitors' browsers.

The vulnerability exists due to improper neutralization of input during web page generation in the Chat Trigger hosted-chat page customCss parameter when rendering author-supplied custom CSS. A remote user can supply crafted custom CSS to execute script in visitors' browsers.

User interaction is required to visit the hosted chat page. Only chat pages published without n8n user authentication are affected.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.83, 2.41.4, 2.42.1

External References

Related Security Bulletins