Executive brief
n8n is a popular workflow automation tool used to connect different business services. A vulnerability in its email-sending component allows attackers to trick the system into reading sensitive local files or making unauthorized network requests. This could lead to the theft of private data or internal system information if a workflow is configured to process untrusted external data.
Technical details
The n8n 'Send Email' node fails to strictly enforce string types for message fields, leading to a type confusion vulnerability. When a non-string object is passed from a workflow expression to the underlying Nodemailer library, it may be interpreted as a file path or URL. An attacker can exploit this via a network-reachable unauthenticated webhook if the workflow maps that input directly into the email body. This allows for arbitrary file disclosure from the n8n host or SSRF. The issue is fixed in versions 1.123.67, 2.31.5, and 2.32.1.
Affected products
- n8n-io n8n < 1.123.67, >= 2.0.0-rc.0 < 2.31.5, >= 2.32.0 < 2.32.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched