VYPR
High severityNVD Advisory· Published Sep 3, 2026

CVE-2026-85170

CVE-2026-85170

Description

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.

Affected products

1
  • N8n Io/N8nllm-fuzzy
    Range: <1.123.73, <2.35.4, <2.36.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.