CVE-2026-72762: n8n: arbitrary file write via Edit Image node format param
UNKNOWNn8n's Edit Image node passes a user-supplied output format value straight into the underlying image processing library without validation, letting an authenticated user who can run workflows write arbitrary files outside the node's sandboxed working directory. This isn't a pre-auth remote exploit — it requires an existing account with workflow execution rights — but n8n is widely used to wire AI agents to external tools and file systems, and workflow authors often include third-party collaborators or lower-trust automation accounts. There's no public exploit or Nuclei template yet, EPSS sits at 0.204% (CISA SSVC rates it TRACK, not immediate action), and it isn't in CISA KEV, so this is not an active-exploitation emergency. Still, arbitrary file write is a classic stepping stone to full compromise (overwriting cron jobs, SSH authorized_keys, or app config), so patch to n8n 1.123.67, 2.31.5, or 2.32.1 and, in the interim, restrict who can create or edit workflows using the Edit Image node.
What is the risk?
Moderate risk. No CVSS vector has been published, but the vulnerability class (CWE-434, unrestricted file write) is high-impact when combined with an authenticated attacker who controls workflow definitions. Exploitation requires a valid n8n account with permission to build/run workflows, which meaningfully limits exposure versus an unauthenticated flaw — most at risk are self-hosted n8n instances with broad workflow-authoring access (shared teams, low-trust automation accounts, or multi-tenant deployments). EPSS (0.204%) and SSVC (TRACK) both indicate low near-term exploitation likelihood, and no public PoC or scanner signature exists yet, but the primitive (arbitrary file write) is reliably escalatable to code execution once weaponized.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| n8n | npm | — | No patch |
Do you use n8n? You're affected.
How severe is it?
What should I do?
1 step-
Upgrade n8n to 1.123.67, 2.31.5, or 2.32.1 immediately where the Edit Image node is in use. Until patched, restrict workflow creation/editing permissions to trusted, vetted users and disable or avoid the Edit Image node for untrusted workflow authors. Audit existing workflows for use of the Edit Image node and unusual/non-standard format parameter values. Monitor the n8n host filesystem for writes outside expected data/working directories, and review file integrity on paths like cron directories, SSH config, and application config files. Run n8n workflow execution with the least-privilege service account possible to limit blast radius of any file write.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72762?
n8n's Edit Image node passes a user-supplied output format value straight into the underlying image processing library without validation, letting an authenticated user who can run workflows write arbitrary files outside the node's sandboxed working directory. This isn't a pre-auth remote exploit — it requires an existing account with workflow execution rights — but n8n is widely used to wire AI agents to external tools and file systems, and workflow authors often include third-party collaborators or lower-trust automation accounts. There's no public exploit or Nuclei template yet, EPSS sits at 0.204% (CISA SSVC rates it TRACK, not immediate action), and it isn't in CISA KEV, so this is not an active-exploitation emergency. Still, arbitrary file write is a classic stepping stone to full compromise (overwriting cron jobs, SSH authorized_keys, or app config), so patch to n8n 1.123.67, 2.31.5, or 2.32.1 and, in the interim, restrict who can create or edit workflows using the Edit Image node.
Is CVE-2026-72762 actively exploited?
No confirmed active exploitation of CVE-2026-72762 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-72762?
Upgrade n8n to 1.123.67, 2.31.5, or 2.32.1 immediately where the Edit Image node is in use. Until patched, restrict workflow creation/editing permissions to trusted, vetted users and disable or avoid the Edit Image node for untrusted workflow authors. Audit existing workflows for use of the Edit Image node and unusual/non-standard format parameter values. Monitor the n8n host filesystem for writes outside expected data/working directories, and review file integrity on paths like cron directories, SSH config, and application config files. Run n8n workflow execution with the least-privilege service account possible to limit blast radius of any file write.
What systems are affected by CVE-2026-72762?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow automation pipelines, plugin/tool integrations.
What is the CVSS score for CVE-2026-72762?
No CVSS score has been assigned yet.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0053 AI Agent Tool Invocation Compliance Controls Affected
What are the technical details?
Original Advisory
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.
Exploitation Scenario
An authenticated n8n user — potentially a lower-trust collaborator, a compromised account, or an AI agent granted workflow-authoring capability — builds or edits a workflow that includes the Edit Image node. Instead of a legitimate image format (e.g., 'png' or 'jpeg'), the attacker supplies a crafted format string that the underlying image library interprets as a path or file directive, causing it to write output outside the node's intended working directory. The attacker uses this to drop a file into a sensitive location — such as overwriting a cron entry, an SSH authorized_keys file, or an n8n configuration file — establishing persistence or escalating to code execution on the n8n host.
Weaknesses (CWE)
CWE-434 Unrestricted Upload of File with Dangerous Type
Primary
CWE-434 Unrestricted Upload of File with Dangerous Type CWE-434 — Unrestricted Upload of File with Dangerous Type: The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
- [Architecture and Design] Generate a new, unique filename for an uploaded file instead of using the user-supplied filename, so that no external input is used at all.[REF-422] [REF-423]
- [Architecture and Design] When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
Source: MITRE CWE corpus.
References
Timeline
Related Vulnerabilities
CVE-2026-33663 10.0 n8n: member role steals plaintext HTTP credentials
Same package: n8n CVE-2026-33660 10.0 TensorFlow: type confusion NPD in tensor conversion
Same package: n8n CVE-2026-21858 10.0 n8n: Input Validation flaw enables exploitation
Same package: n8n CVE-2026-27577 9.9 n8n: Code Injection enables RCE
Same package: n8n CVE-2026-27494 9.9 n8n: security flaw enables exploitation
Same package: n8n