n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-233r-fpgw-fx8x | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-ssrf-via-edit-image-node | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-20 12:16
Updated : 2026-09-01 19:34
NVD link : CVE-2026-77074
Mitre link : CVE-2026-77074
CVE.ORG link : CVE-2026-77074
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
