CVE-2026-85170

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 13:06

Updated : 2026-09-08 20:10


NVD link : CVE-2026-85170

Mitre link : CVE-2026-85170

CVE.ORG link : CVE-2026-85170


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation