CVE-2025-56265: n8n
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
Affected products
- n8n n8n: version 1.95.3 only; version 1.100.1 only; version 1.101.1 only
Published 2025-09-08. Last modified 2026-06-17.