Junglewise Threat Intelligence

CVE-2026-72766: n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does n

CVE-2026-72766 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that enables users to build and run integrations combining visual workflows with custom code. The Send Email node within n8n failed to validate that email message fields were plain text strings, which allowed attackers to craft special input values that the underlying mail library would treat as file paths or remote URLs instead of message content. An attacker with access to an exposed webhook endpoint could exploit this to read sensitive files from the server or make network requests to internal systems, potentially exposing confidential data.

Technical details

The vulnerability stems from a type-confusion issue in n8n's Send Email node where input validation was not enforced on message body fields. The Nodemailer mail library, when receiving non-string values for the text or HTML body, interprets them as file paths or URLs and attempts to fetch their contents. This affects all versions prior to 1.123.67, 2.31.5, and 2.32.1. Exploitation requires: (1) an active workflow with an unauthenticated webhook trigger, (2) valid SMTP credentials configured on the Send Email node, and (3) untrusted input (from the webhook or external data source) directly mapped into the email body fields. The attack vector is network-accessible, targeting the webhook endpoint. Successful exploitation allows an attacker to read arbitrary local files on the n8n host or trigger server-side request forgery (SSRF) attacks. The issue was patched by adding type validation to enforce string-only values for message fields.

Affected products

  • n8n n8n < 1.123.67, >= 2.0.0-rc.0 < 2.31.5, >= 2.32.0 < 2.32.1

Timeline

  • 2026-07-22: disclosed: Advisory published
  • 2026-07-22: patched: Fixes released in versions 1.123.67, 2.31.5, and 2.32.1

References

Related threats