CVE-2025-52478 Information
Aug 20, 2025
cve
Description
n8n is a workflow automation platform. From 1.77.0 to before 1.98.2 a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n specifically in the Form Trigger node’s HTML form element. An authenticated attacker can inject malicious HTML via an
Reference
https://github.com/n8n-io/n8n/commit/7940384a85041a1890b1203d69c092c887312500 https://github.com/n8n-io/n8n/pull/16329 https://github.com/n8n-io/n8n/security/advisories/GHSA-hfmv-hhh3-43f2
Related CNNVD
CNNVD-202508-2180 (Published: 2025-08-19)
Share on: