PT-2026-70164 · N8N · N8N

·

CVE-2026-72762

·

Published

2026-07-22

·

Updated

2026-08-11

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.67 n8n versions prior to 2.31.5 n8n versions prior to 2.32.1
Description An arbitrary file write issue exists in the Edit Image node. The node passes the output format parameter to the underlying image library without proper validation. An authenticated user with permissions to execute workflows can provide a specially crafted value for the output format to write files outside the designated working directory of the n8n instance.
Recommendations Update n8n to version 1.123.67 or later. Update n8n to version 2.31.5 or later. Update n8n to version 2.32.1 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72762
GHSA-XMC9-4F2H-JF9C

Affected Products

N8N