CVE-2026-85170

HIGH CVSS 4.0: 7.1 EPSS 0.23%
Updated Sep 18, 2026
N8N
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions 2.0.0 — 2.36.2
Fixed In 1.123.73
Type CWE-20 (Improper Input Validation)
Vendor N8N
Public PoC No

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 6

Configuration From (including) Up to (excluding)
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
1.123.73
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
2.36.2
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
2.35.4
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
1.123.73
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
2.0.0 2.35.4
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
2.36.0 2.36.2