An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| @n8n/n8n-nodes-langchain(npm) | 0 | 1.107.0 | N/A |
CVSS Metrics