CVE-2026-72762
published 2026-08-11CVE-2026-72762: n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.26%
18.3th percentile
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| n8n-io | n8n | < 1.123.67 | 1.123.67 |
| n8n-io | n8n | < 2.32.1 | 2.32.1 |
| n8n-io | n8n | < 2.31.5 | 2.31.5 |
| n8n | n8n | < 1.123.67 | 1.123.67 |
| n8n | n8n | — | — |
| n8n | n8n | >= 2.0.0 < 2.31.5 | 2.31.5 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
n8n-io n8n Edit Image Node format file inclusion
vuldb·2026-09-11·CVSS 7.7
CVE-2026-72762 [HIGH] n8n-io n8n Edit Image Node format file inclusion
A vulnerability was found in n8n-io n8n and classified as critical. The impacted element is an unknown function of the component Edit Image Node. The manipulation of the argument format results in file inclusion.
This vulnerability was named CVE-2026-72762. The attack may be performed from remote. There is no available exploit.
GHSA
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without
ghsa_unreviewed·2026-08-11
CVE-2026-72762 [HIGH] CWE-434 n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published