Skip to content

CVE-2026-56358

Cross-site Scripting: is CVE-2026-56358real, exploitable, or a false positive? Here's the community verdict.

Medium · CVSS 5.4CWE-79 · Cross-site Scripting

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.

Published

Embed this verdict
TruePositive verdict for CVE-2026-56358
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2026-56358/badge.svg)](https://www.truepositive.app/cve/CVE-2026-56358)
HTML
<a href="https://www.truepositive.app/cve/CVE-2026-56358"><img src="https://www.truepositive.app/cve/CVE-2026-56358/badge.svg" alt="TruePositive verdict for CVE-2026-56358"></a>

Live badge that updates automatically as the community verdict changes.

Community ground truth

In your experience, is this finding real and exploitable?

0 verdicts
Not a real issue

No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.

Field notes & remediation

Verdicts are the quick signal. Notes are the evidence and fixes behind them.

No notes yet. Be the first to share what you saw, or a fix that worked.

    Add a field note or remediationoptional
    Note type

    What are you adding?

    Markdown supported · minimum 20 characters.

    Same weakness: CWE-79 · Cross-site Scripting.