PT-2026-85002 · N8N · N8N

·

CVE-2026-85170

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.73 n8n versions prior to 2.35.4 n8n versions prior to 2.36.2
Description Authenticated users with workflow execution privileges can exploit the Gmail (v1) and Brevo nodes by providing an expression that resolves to an object containing a path or href property. Because the mail composer does not verify that the message content is a string, it may read a local file accessible to the process or perform a Server-Side Request Forgery (SSRF)—where the server is coerced into making an unauthorized request to an internal URL—and attach the resulting data to the outgoing message.
Recommendations Update to version 1.123.73 or later. Update to version 2.35.4 or later. Update to version 2.36.2 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85170
GHSA-95PH-833C-4WRP

Affected Products

N8N