CVE-2026-77072: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in n8n-io n8n
Description
n8n versions prior to 1.123.69, 2.33.4, and 2.34.1 contain a stored cross-site scripting (XSS) vulnerability in the Form node's completion page. This vulnerability arises because the completion page applies its Content-Security-Policy sandbox only when respondWith is not set to 'redirect', but always renders responseText as raw HTML. An authenticated user can exploit this by setting respondWith to 'redirect' while keeping responseText populated, causing unsanitized HTML and scripts to be served from the n8n origin. Visitors submitting the affected public form may have malicious scripts execute in their session context.
CVSS v4.0
Score 8.4high
Affected software
n8n-io
n8n
n8n-io
n8n
n8n-io
n8n
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-77072 is a stored cross-site scripting vulnerability in n8n's Form node completion page. The issue occurs because the Content-Security-Policy sandbox is conditionally applied based on the respondWith parameter, but responseText is always rendered as raw HTML. An authenticated user can manipulate respondWith to 'redirect' and supply malicious HTML/script in responseText, resulting in unsanitized content served from the n8n origin. This allows script execution in the context of any visitor submitting the public form, potentially compromising their session.
Potential Impact
This vulnerability allows an authenticated user to inject malicious scripts into the Form node's completion page, which are then executed in the browser of any visitor submitting the affected public form. This can lead to session hijacking, unauthorized actions, or other impacts typical of stored cross-site scripting attacks. The vulnerability affects confidentiality and integrity of user sessions interacting with the public form.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, avoid using the Form node's completion page with respondWith set to 'redirect' in environments where untrusted users can submit forms. Monitor vendor communications for patches or updates addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-20T10:51:39.783Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a86e706acd9273b498befae
Added to database: 08/20/2026, 11:37:42 UTC
Last enriched: 09/11/2026, 01:47:31 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.