PT-2026-78928 · N8N · N8N

·

CVE-2026-77072

·

Published

2026-08-20

·

Updated

2026-09-01

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.69 n8n versions prior to 2.33.4 n8n versions prior to 2.34.1
Description A stored cross-site scripting issue exists in the Form node completion page. The system only applied its sandboxing Content-Security-Policy (a security layer that helps detect and mitigate certain types of attacks, including XSS) when the respondWith variable was not set to 'redirect'. However, the responseText variable was always rendered as raw HTML. An authenticated member could use an expression to set respondWith to 'redirect' while keeping responseText populated, leading the completion page to serve unsanitized HTML and scripts from the n8n origin. Consequently, any visitor submitting the public form would execute that script within their own session.
Recommendations Update n8n to version 1.123.69 or later. Update n8n to version 2.33.4 or later. Update n8n to version 2.34.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77072
GHSA-RMR5-775F-JVM2

Affected Products

N8N