Описание
N8N's Chat Trigger component is vulnerable to XSS
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
Пакеты
Наименование
@n8n/n8n-nodes-langchain
npm
Затронутые версииВерсия исправления
< 1.107.0
1.107.0
Связанные уязвимости
CVSS3: 8.8
nvd
5 месяцев назад
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.