PT-2025-37731 · N8N · N8N+1

5H0Lm3S

+1

·

Publicado

2025-09-15

·

Atualizado

2025-10-14

·

CVE-2025-58177

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions n8n versions 1.24.0 through 1.106.0
Description n8n is a workflow automation platform. A stored cross-site scripting (XSS) vulnerability exists in the @n8n/n8n-nodes-langchain.chatTrigger node. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages field and enable public access, leading to payload execution in the browser of any user who visits the resulting public chat URL. This could be used for phishing or to steal cookies or other sensitive data from users accessing the public chat link.
Recommendations Update to version 1.107.0 or later. As a workaround, disable the @n8n/n8n-nodes-langchain.chatTrigger node.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-58177
GHSA-MVH4-2CM2-6HPG

Produtos afetados

@N8N/N8N-Nodes-Langchain.Chattrigger
N8N