CVE-2026-56356: n8n

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page.

Affected products

  • n8n n8n: before 1.123.27 (fixed in 1.123.27); from 2.0.0, before 2.13.3 (fixed in 2.13.3); version 2.14.0 only

Published 2026-06-30. Last modified 2026-07-02.