High severity8.8NVD Advisory· Published Sep 8, 2025· Updated Jun 17, 2026
CVE-2025-56265
CVE-2025-56265
Description
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@n8n/n8n-nodes-langchainnpm | < 1.107.0 | 1.107.0 |
Affected products
2- N8N/N8Ndescription
Patches
Vulnerability mechanics
References
7- github.com/nikolas-ch/CVEs/tree/main/N8N/N8N_v1.100.1nvdExploit
- github.com/nikolas-ch/CVEs/tree/main/N8N/N8N_v1.100.1/ChatTrigger_StoredXSSviaUnrestrictedFileUploadnvdExploit
- github.com/advisories/GHSA-v2x8-97xq-8xrrghsaADVISORY
- github.com/nikolas-ch/CVEs/blob/main/N8N/N8N_v1.100.1/ChatTrigger_StoredXSSviaUnrestrictedFileUpload/StoredXSSviaUnristrictedFileUpload.txtnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-56265ghsaADVISORY
- github.com/n8n-io/n8n/pull/18148ghsaWEB
- github.com/n8n-io/n8n/releases/tag/n8n%401.107.0ghsaWEB
News mentions
0No linked articles in our index yet.