Junglewise Threat Intelligence

CVE-2025-58177: n8n LangChain Chat Trigger Node stored XSS in initialMessages

CVE-2025-58177 · Severity: low · CVSS 3.1 · Published 2025-09-15

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create complex business processes. The LangChain Chat Trigger node enables public chat interfaces for end users. An attacker with access to configure this node can inject malicious JavaScript that executes in the browsers of any visitor to the public chat link, allowing phishing attacks or theft of sensitive data like cookies.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the @n8n/n8n-nodes-langchain chatTrigger node in n8n versions 1.24.0 through 1.106.x. The vulnerability is triggered when an authorized user enters malicious JavaScript in the initialMessages parameter field and enables public access for the chat node. The unfiltered input is reflected in the browser of any user who visits the public chat URL, allowing arbitrary JavaScript execution. An attacker must have authorization to configure n8n workflows and the target user must visit the public chat link, requiring user interaction. The vulnerability has been patched in version 1.107.0.

Affected products

  • n8n n8n 1.24.0 to 1.106.x

Timeline

  • 2025-09-15: disclosed: Advisory published
  • 2025-09-15: patched: Patched in version 1.107.0

References

Related threats