Arbitrary File Write Vulnerability in n8n by n8n-io
CVE-2026-72762

7.7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72762?

The Edit Image node in n8n versions prior to 1.123.67, 2.31.5, and 2.32.1 is susceptible to an arbitrary file write vulnerability, where an authenticated user can manipulate the output format parameter. This flaw allows the user to provide a crafted format value, enabling them to create or overwrite files outside of the node's designated working directory on the n8n instance, potentially compromising the integrity of the system.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

simonkoeck
.