PT-2026-78928 · N8N · N8N
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.69
n8n versions prior to 2.33.4
n8n versions prior to 2.34.1
Description
A stored cross-site scripting issue exists in the Form node completion page. The system only applied its sandboxing Content-Security-Policy (a security layer that helps detect and mitigate certain types of attacks, including XSS) when the
respondWith variable was not set to 'redirect'. However, the responseText variable was always rendered as raw HTML. An authenticated member could use an expression to set respondWith to 'redirect' while keeping responseText populated, leading the completion page to serve unsanitized HTML and scripts from the n8n origin. Consequently, any visitor submitting the public form would execute that script within their own session.Recommendations
Update n8n to version 1.123.69 or later.
Update n8n to version 2.33.4 or later.
Update n8n to version 2.34.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N