Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-29216 | Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter |
![]() |
GHSA-mvh4-2cm2-6hpg | Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 14 Oct 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
N8n
N8n n8n |
|
Vendors & Products |
N8n
N8n n8n |
Mon, 15 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 15 Sep 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages field and enable public access so that the payload is executed in the browser of any user who visits the resulting public chat URL. This can be used for phishing or to steal cookies or other sensitive data from users accessing the public chat link. The issue is fixed in version 1.107.0. Updating to 1.107.0 or later is recommended. As a workaround, the affected chatTrigger node can be disabled. No other workarounds are known. | |
Title | n8n stored cross-site scripting in LangChain Chat Trigger node initialMessages parameter | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-15T17:27:13.707Z
Reserved: 2025-08-27T13:34:56.189Z
Link: CVE-2025-58177

Updated: 2025-09-15T17:27:05.943Z

Status : Analyzed
Published: 2025-09-15T17:15:35.783
Modified: 2025-10-14T19:34:18.003
Link: CVE-2025-58177

No data.

Updated: 2025-09-17T10:52:21Z