Impact
This vulnerability resides in the Gmail (v1) and Brevo nodes of n8n and allows an authenticated user who can run a workflow to supply an expression that resolves to an object with a path or href property. The mail composer receives this unsanitized content and attempts to read the specified local file or fetch the internal URL, thereby exposing local file contents or internal network resources to the attacker. The weakness is a classic unchecked input that can be exploited for local file read or server‑side request forgery, potentially exposing sensitive data or enabling further lateral movement within the host environment.
Affected Systems
n8n versions prior to 1.123.73, 2.35.4, and 2.36.2 are impacted. The affected product is n8n, a workflow automation tool released by n8n‑io, Inc.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk rating. There is no EPSS score available, so the current explosion probability cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires authenticated access to the n8n instance, meaning an insider or a compromised account could trigger the read or SSRF by creating a malicious workflow. No public exploits have been reported, but the flaw is severe enough to necessitate rapid remediation.
OpenCVE Enrichment