Логотип exploitDog
bind:CVE-2025-58177
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-58177

Количество 2

Количество 2

nvd логотип

CVE-2025-58177

5 месяцев назад

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages field and enable public access so that the payload is executed in the browser of any user who visits the resulting public chat URL. This can be used for phishing or to steal cookies or other sensitive data from users accessing the public chat link. The issue is fixed in version 1.107.0. Updating to 1.107.0 or later is recommended. As a workaround, the affected chatTrigger node can be disabled. No other workarounds are known.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mvh4-2cm2-6hpg

5 месяцев назад

Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter

CVSS3: 4.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-58177

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages field and enable public access so that the payload is executed in the browser of any user who visits the resulting public chat URL. This can be used for phishing or to steal cookies or other sensitive data from users accessing the public chat link. The issue is fixed in version 1.107.0. Updating to 1.107.0 or later is recommended. As a workaround, the affected chatTrigger node can be disabled. No other workarounds are known.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-mvh4-2cm2-6hpg

Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter

CVSS3: 4.1
0%
Низкий
5 месяцев назад

Уязвимостей на страницу