Cross-site scripting in n8n - #VU153006
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute script in visitors' browsers.
The vulnerability exists due to improper neutralization of input during web page generation in the Chat Trigger hosted-chat page customCss parameter when rendering author-supplied custom CSS. A remote user can supply crafted custom CSS to execute script in visitors' browsers.
User interaction is required to visit the hosted chat page. Only chat pages published without n8n user authentication are affected.