Server-Side Request Forgery in n8n's Image Processing Functionality
CVE-2026-77074

6MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77074?

A vulnerability exists in n8n prior to version 1.123.69 that allows authenticated users to perform server-side request forgery (SSRF) via the Edit Image node's Draw Text operation. This flaw can be exploited by attackers to submit crafted text inputs, leading to the execution of outbound HTTP requests to unauthorized locations or unauthorized file access on local systems.

Affected Version(s)

n8n 0 < 1.123.69

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.