CVE-2026-72762: n8n: arbitrary file write via Edit Image node format param

UNKNOWN
Published August 11, 2026
CISO Take

n8n's Edit Image node passes a user-supplied output format value straight into the underlying image processing library without validation, letting an authenticated user who can run workflows write arbitrary files outside the node's sandboxed working directory. This isn't a pre-auth remote exploit — it requires an existing account with workflow execution rights — but n8n is widely used to wire AI agents to external tools and file systems, and workflow authors often include third-party collaborators or lower-trust automation accounts. There's no public exploit or Nuclei template yet, EPSS sits at 0.204% (CISA SSVC rates it TRACK, not immediate action), and it isn't in CISA KEV, so this is not an active-exploitation emergency. Still, arbitrary file write is a classic stepping stone to full compromise (overwriting cron jobs, SSH authorized_keys, or app config), so patch to n8n 1.123.67, 2.31.5, or 2.32.1 and, in the interim, restrict who can create or edit workflows using the Edit Image node.

Sources: NVD GitHub Advisory EPSS ATLAS vulncheck.com

What is the risk?

Moderate risk. No CVSS vector has been published, but the vulnerability class (CWE-434, unrestricted file write) is high-impact when combined with an authenticated attacker who controls workflow definitions. Exploitation requires a valid n8n account with permission to build/run workflows, which meaningfully limits exposure versus an unauthenticated flaw — most at risk are self-hosted n8n instances with broad workflow-authoring access (shared teams, low-trust automation accounts, or multi-tenant deployments). EPSS (0.204%) and SSVC (TRACK) both indicate low near-term exploitation likelihood, and no public PoC or scanner signature exists yet, but the primitive (arbitrary file write) is reliably escalatable to code execution once weaponized.

How does the attack unfold?

Initial Access
Attacker obtains or already holds an authenticated n8n account with permission to create and run workflows.
AML.T0012
Exploitation
Attacker builds a workflow using the Edit Image node and supplies a crafted output format value that is passed unsanitized to the underlying image library.
AML.T0053
Impact
The crafted format value causes an arbitrary file write outside the node's working directory, enabling tampering with configuration, credentials, or persistence mechanisms on the n8n host.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
n8n npm — No patch
206.1K OpenSSF 6.7 Pushed 5d ago 53% patched ~5d to patch Full package profile →

Do you use n8n? You're affected.

How severe is it?

CVSS 3.1
N/A
EPSS
0.5%
chance of exploitation in 30 days
Higher than 39% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What should I do?

1 step
  1. Upgrade n8n to 1.123.67, 2.31.5, or 2.32.1 immediately where the Edit Image node is in use. Until patched, restrict workflow creation/editing permissions to trusted, vetted users and disable or avoid the Edit Image node for untrusted workflow authors. Audit existing workflows for use of the Edit Image node and unusual/non-standard format parameter values. Monitor the n8n host filesystem for writes outside expected data/working directories, and review file integrity on paths like cron directories, SSH config, and application config files. Run n8n workflow execution with the least-privilege service account possible to limit blast radius of any file write.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact total

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Code Execution Agent Plugin AML.T0053

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.6.2.4 - AI system security controls
NIST AI RMF
MANAGE 4.1 - Third-party risks are managed
OWASP LLM Top 10
LLM07 - Insecure Plugin Design

Frequently Asked Questions

What is CVE-2026-72762?

n8n's Edit Image node passes a user-supplied output format value straight into the underlying image processing library without validation, letting an authenticated user who can run workflows write arbitrary files outside the node's sandboxed working directory. This isn't a pre-auth remote exploit — it requires an existing account with workflow execution rights — but n8n is widely used to wire AI agents to external tools and file systems, and workflow authors often include third-party collaborators or lower-trust automation accounts. There's no public exploit or Nuclei template yet, EPSS sits at 0.204% (CISA SSVC rates it TRACK, not immediate action), and it isn't in CISA KEV, so this is not an active-exploitation emergency. Still, arbitrary file write is a classic stepping stone to full compromise (overwriting cron jobs, SSH authorized_keys, or app config), so patch to n8n 1.123.67, 2.31.5, or 2.32.1 and, in the interim, restrict who can create or edit workflows using the Edit Image node.

Is CVE-2026-72762 actively exploited?

No confirmed active exploitation of CVE-2026-72762 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-72762?

Upgrade n8n to 1.123.67, 2.31.5, or 2.32.1 immediately where the Edit Image node is in use. Until patched, restrict workflow creation/editing permissions to trusted, vetted users and disable or avoid the Edit Image node for untrusted workflow authors. Audit existing workflows for use of the Edit Image node and unusual/non-standard format parameter values. Monitor the n8n host filesystem for writes outside expected data/working directories, and review file integrity on paths like cron directories, SSH config, and application config files. Run n8n workflow execution with the least-privilege service account possible to limit blast radius of any file write.

What systems are affected by CVE-2026-72762?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow automation pipelines, plugin/tool integrations.

What is the CVSS score for CVE-2026-72762?

No CVSS score has been assigned yet.

What is the AI security impact?

Affected AI Architectures

agent frameworksworkflow automation pipelinesplugin/tool integrations

MITRE ATLAS Techniques

AML.T0053 AI Agent Tool Invocation

Compliance Controls Affected

ISO 42001: A.6.2.4
NIST AI RMF: MANAGE 4.1
OWASP LLM Top 10: LLM07

What are the technical details?

Original Advisory

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.

Exploitation Scenario

An authenticated n8n user — potentially a lower-trust collaborator, a compromised account, or an AI agent granted workflow-authoring capability — builds or edits a workflow that includes the Edit Image node. Instead of a legitimate image format (e.g., 'png' or 'jpeg'), the attacker supplies a crafted format string that the underlying image library interprets as a path or file directive, causing it to write output outside the node's intended working directory. The attacker uses this to drop a file into a sensitive location — such as overwriting a cron entry, an SSH authorized_keys file, or an n8n configuration file — establishing persistence or escalating to code execution on the n8n host.

Weaknesses (CWE)

CWE-434 — Unrestricted Upload of File with Dangerous Type: The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

  • [Architecture and Design] Generate a new, unique filename for an uploaded file instead of using the user-supplied filename, so that no external input is used at all.[REF-422] [REF-423]
  • [Architecture and Design] When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.

Source: MITRE CWE corpus.

Timeline

Published
August 11, 2026
Last Modified
September 9, 2026
First Seen
August 11, 2026

Related Vulnerabilities