Loading market data...
← Back to CVE feed

CVE-2026-85170

UNKNOWN View on NVD ↗

Description

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.

Published: Sep 03, 2026 13:06 UTC Modified: Sep 03, 2026 13:06 UTC