PT-2025-36488 · N8N · N8N

·

CVE-2025-56265

·

Published

2025-09-08

·

Updated

2025-09-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: N8N versions 1.95.3, 1.100.1, and 1.101.1
Description: An arbitrary file upload vulnerability exists in the Chat Trigger component of N8N. This allows attackers to execute arbitrary code by uploading a crafted HTML file.
Recommendations: Update N8N to a version newer than 1.95.3. Update N8N to a version newer than 1.100.1. Update N8N to a version newer than 1.101.1.

Exploit

Fix

RCE

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56265
GHSA-V2X8-97XQ-8XRR

Affected Products

N8N