6.5

CVE-2026-85170

n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
N8n ≫ N8n SwPlatform node.js Version < 1.123.73
N8n ≫ N8n SwPlatform node.js Version >= 2.0.0 < 2.35.4
N8n ≫ N8n SwPlatform node.js Version >= 2.36.0 < 2.36.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.142
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
disclosure@vulncheck.com 7.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/n8n-io/n8n/security/advisories/GHSA-95ph-833c-4wrp
Vendor Advisory
Mitigation
https://www.vulncheck.com/advisories/n8n-before-1.123.73-local-file-read-and-ssrf-via-gmail-and-brevo-nodes
Third Party Advisory