Junglewise Threat Intelligence

CVE-2025-56265: N8N Chat Trigger arbitrary file upload and XSS

CVE-2025-56265 · Severity: low · CVSS 3.1 · Published 2025-09-08

Technologies: N8n. Vendors: N8n, npm.

Executive brief

N8N is an automation platform that allows users to build workflows through a visual interface. The Chat Trigger component, used to handle chat interactions within workflows, contains a vulnerability that allows attackers to upload malicious HTML files containing executable code. This could enable attackers with login access to execute arbitrary code, potentially compromising the entire automation platform and any data it processes.

Technical details

The vulnerability is a combination of unrestricted file upload (CWE-434) and cross-site scripting (CWE-79) in the Chat Trigger node. Attackers can upload specially crafted HTML files that execute arbitrary code when the file is processed or displayed. The issue affects N8N versions 1.95.3, 1.100.1, and 1.101.1. The vulnerability requires authentication (PR:L - low privilege) to exploit, as an attacker needs platform access to upload files via the Chat Trigger component. The fix was implemented in version 1.107.0 with input sanitization of initialMessages and i18n configuration values, along with improved parameter validation.

Affected products

  • N8N n8n 1.95.3, 1.100.1, 1.101.1 (fixed in 1.107.0)

Timeline

  • 2025-09-08: disclosed: GHSA advisory published
  • 2025-09-10: patched: GitHub advisory reviewed; fix available in version 1.107.0
  • 2025-08-11: other: Fix merged into master branch

References

Related threats