CVE-2026-72766
Description
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF). Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the node, and untrusted input mapped directly into the body field; this is not a default configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/n8n-io/n8n/security/advisories/GHSA-2x35-3fw4-9jr4nvdVendor AdvisoryMitigation
- www.vulncheck.com/advisories/n8n-before-arbitrary-file-read-via-send-email-nodenvdThird Party Advisory
News mentions
1- N8n: 16 Vulnerabilities Including RCE and SQLi Disclosed in Single BatchVypr Intelligence · Aug 11, 2026