Junglewise Threat Intelligence

CVE-2026-72762: n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its outp

CVE-2026-72762 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform used to orchestrate business processes and integrations across services. The Edit Image node in n8n does not properly validate user-supplied image format parameters before passing them to the underlying image processing library. An authenticated user can exploit this to write arbitrary files anywhere on the n8n server, potentially compromising the entire workflow system and exposing sensitive data.

Technical details

The vulnerability is a format injection flaw (CWE-73) in n8n's Edit Image node. The node accepts a user-controlled output format parameter and passes it directly to an underlying image library without validation or sanitization. This allows an authenticated attacker to craft a malicious format value that causes the image library to write bytes to arbitrary file paths outside the intended working directory. The attack requires authentication and the ability to execute workflows, but no user interaction beyond crafting the malicious workflow. Successful exploitation allows arbitrary file write as the n8n process user, potentially achieving code execution or data exfiltration. Patches are available in versions 1.123.67, 2.31.5, and 2.32.1 or later.

Affected products

  • n8n n8n all versions prior to 1.123.67, 2.0.0-rc.0 to before 2.31.5, and 2.32.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: patched: Versions 1.123.67, 2.31.5, and 2.32.1 or later contain fixes

References

Related threats