Arbitrary File Write Vulnerability in n8n by n8n-io
CVE-2026-72762
7.7HIGH
What is CVE-2026-72762?
The Edit Image node in n8n versions prior to 1.123.67, 2.31.5, and 2.32.1 is susceptible to an arbitrary file write vulnerability, where an authenticated user can manipulate the output format parameter. This flaw allows the user to provide a crafted format value, enabling them to create or overwrite files outside of the node's designated working directory on the n8n instance, potentially compromising the integrity of the system.
Affected Version(s)
n8n 0 < 1.123.67
n8n 0 < 2.32.1
n8n 0 < 2.31.5
