Impact
The Edit Image node’s Draw Text operation in n8n allows authenticated users to inject MVG primitives, enabling blind outbound HTTP requests to arbitrary addresses or access to local files on the host. This flaw is a form of server‑side request forgery, exemplifying code injection (CWE‑94) within the node’s handling of user‑supplied text parameters.
Affected Systems
n8n versions before 1.123.69 are affected. The product is n8n from n8n‑io; any deployment running an older package dated prior to 1.123.69 is vulnerable. No further version granularity is provided.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. Attackers must possess valid authenticated credentials on the platform, but once authenticated they can craft malicious text to trigger blind outbound connections or insecure local file reads. The required conditions are thus satisfied in environments where user access is present, raising a realistic risk for those deployments.
OpenCVE Enrichment