CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:1.95.3:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:1.100.1:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:1.101.1:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2025-09-08 18:15

Updated : 2025-09-12 20:47


NVD link : CVE-2025-56265

Mitre link : CVE-2025-56265

CVE.ORG link : CVE-2025-56265


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type