An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
| Software | From | Fixed in |
|---|---|---|
@n8n / n8n-nodes-langchain
|
- | 1.107.0 |
| n8n / n8n | 1.95.3 | 1.95.3.x |
| n8n / n8n | 1.100.1 | 1.100.1.x |
| n8n / n8n | 1.101.1 | 1.101.1.x |