Junglewise Threat Intelligence

n8n arbitrary file write in Edit Image node

Severity: high · CVSS 7.7 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a popular workflow automation tool used to connect different software services. A vulnerability in its image editing component allows an authorized user to write files to unauthorized locations on the server. This could lead to a complete system takeover or the corruption of critical application files.

Technical details

The n8n 'Edit Image' node fails to validate the output format parameter before passing it to the underlying image processing library. This lack of sanitization allows for a path traversal or format injection attack (CWE-73). An authenticated attacker with permissions to create or execute workflows can provide a specially crafted value to write arbitrary bytes to locations outside the node's intended working directory. This can result in arbitrary file creation or overwriting on the n8n instance. The issue is resolved in versions 1.123.67, 2.31.5, and 2.32.1.

Affected products

  • n8n-io n8n < 1.123.67, >= 2.0.0-rc.0 < 2.31.5, >= 2.32.0 < 2.32.1

Timeline

  • 2026-07-22: advisory: GitHub Advisory GHSA-xmc9-4f2h-jf9c published
  • 2026-07-22: patched: Fixes released in multiple version branches

References

Related threats