Impact
The flaw lies in the Edit Image node of n8n, where an authenticated user can instruct the underlying image library to use a crafted output format value without any validation. This allows the user to write files to arbitrary locations on the node’s file system outside the node’s designated working directory, enabling modification or creation of system files. The vulnerability is a classic arbitrary file write (CWE-434).
Affected Systems
The issue affects n8n versions before 1.123.67, before 2.31.5, and before 2.32.1. Users deploying any of these releases are potentially exposed if they grant workflow execution privileges to authenticated users.
Risk and Exploitability
With a CVSS score of 7.7, the vulnerability is considered high severity. Because an attacker must be authenticated and able to execute workflows, the attack vector is likely an authenticated remote user or an insider with sufficient privileges. EPSS data is not available, and the threat is not listed in the CISA KEV catalog, suggesting that observed exploitation may not yet be widespread but the risk remains significant for any environment using the affected releases.
OpenCVE Enrichment