CVE-2026-72766: n8n: Send Email node type confusion enables SSRF, LFI

HIGH
Published August 11, 2026
CISO Take

n8n's Send Email node fails to enforce that message body fields are strings, letting a crafted non-string value from a workflow expression be misread by the underlying Nodemailer library as a file path or URL — enabling arbitrary local file disclosure or server-side request forgery. The blast radius is real but narrow: exploitation requires a specific combination already present in the target environment — an active workflow with an unauthenticated webhook, SMTP credentials configured on the Send Email node, and untrusted input mapped directly into the body field — so this is not exploitable by default and depends entirely on how a given workflow was built. There's no public exploit code, no Nuclei template, it's absent from CISA KEV, and the EPSS score of 0.28% signals low near-term exploitation probability, consistent with CISA's own SSVC 'Track' decision (monitor, don't scramble). Given n8n's growing footprint as an AI agent orchestration platform where workflows routinely wire external webhook triggers into notification nodes, security teams should still audit existing workflows for this exact webhook-to-SMTP-node pattern rather than assume the missing CVSS score means it's unimportant. Patch to n8n 1.123.67, 2.31.5, or 2.32.1, and until then validate or coerce email body fields to strings before they reach the Send Email node in any workflow reachable from an unauthenticated trigger.

Sources: NVD GitHub Advisory EPSS CISA KEV ATLAS vulncheck.com

What is the risk?

Overall aggregate risk is low-to-moderate but can be high for specific misconfigured workflows. No CVSS score has been assigned, the vulnerability is absent from CISA KEV, there is no public PoC or Nuclei scanner coverage, and EPSS (0.28%) places it well within the low-probability range for near-term mass exploitation. However, the required preconditions — an unauthenticated webhook trigger, valid SMTP credentials on the Send Email node, and unsanitized input flowing into the body/HTML field — describe a realistic and common automation pattern (e.g., 'form submission triggers a notification email'). Where that pattern exists, impact is significant: arbitrary local file read can expose n8n's `.env`, credentials, or SSH keys, and SSRF can pivot into internal networks or cloud metadata endpoints. CISA's TRACK SSVC decision is appropriate at the ecosystem level, but individual n8n operators exposing webhooks publicly should treat this as urgent, workflow-specific risk rather than a low-priority CVE.

How does the attack unfold?

Initial access
Attacker sends a crafted request to an unauthenticated n8n webhook that triggers a workflow containing a Send Email node.
AML.T0049
Type confusion exploitation
The workflow maps the attacker-controlled input directly into the email body/HTML field without enforcing it as a string, and Nodemailer misinterprets the crafted value as a file path or URL.
Impact
Depending on the crafted field, Nodemailer either reads and includes an arbitrary local file in the outgoing email or issues an outbound SSRF request to an internal service or cloud metadata endpoint.
AML.T0025
Secondary compromise
Leaked local files (.env, SSH keys) or SSRF-harvested cloud metadata credentials enable further lateral movement or account takeover beyond the n8n host.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
n8n npm — No patch
206.1K OpenSSF 6.7 Pushed 5d ago 53% patched ~5d to patch Full package profile →

Do you use n8n? You're affected.

How severe is it?

CVSS 3.1
7.5 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 36% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Unchanged
C High
I None
A None

What should I do?

1 step
  1. Patch immediately: upgrade to n8n 1.123.67 (1.x line), 2.31.5 (2.x line), or 2.32.1 (2.32.x line) — all affected release lines have fixed versions. Until patched, audit all active workflows for the vulnerable pattern: an unauthenticated webhook trigger feeding a Send Email node with SMTP credentials configured, where the text/HTML body is built from an expression referencing webhook or trigger data instead of a static string. Where found, either disable or authenticate the webhook, or explicitly cast/validate the body field to a string before deployment. For detection, monitor SMTP/outbound logs for anomalous local file paths or unexpected internal/metadata IP addresses appearing in message content, and audit .env/credential files for signs of exfiltration if a vulnerable workflow was internet-facing. Restrict outbound network access (egress filtering) from the n8n host as defense-in-depth against the SSRF component.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable Yes
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.6.2.6 - Security of AI system components and infrastructure
NIST AI RMF
MANAGE-4.1 - AI system risks are monitored and risk response actions are taken
OWASP LLM Top 10
LLM07 - Insecure Plugin Design

Frequently Asked Questions

What is CVE-2026-72766?

n8n's Send Email node fails to enforce that message body fields are strings, letting a crafted non-string value from a workflow expression be misread by the underlying Nodemailer library as a file path or URL — enabling arbitrary local file disclosure or server-side request forgery. The blast radius is real but narrow: exploitation requires a specific combination already present in the target environment — an active workflow with an unauthenticated webhook, SMTP credentials configured on the Send Email node, and untrusted input mapped directly into the body field — so this is not exploitable by default and depends entirely on how a given workflow was built. There's no public exploit code, no Nuclei template, it's absent from CISA KEV, and the EPSS score of 0.28% signals low near-term exploitation probability, consistent with CISA's own SSVC 'Track' decision (monitor, don't scramble). Given n8n's growing footprint as an AI agent orchestration platform where workflows routinely wire external webhook triggers into notification nodes, security teams should still audit existing workflows for this exact webhook-to-SMTP-node pattern rather than assume the missing CVSS score means it's unimportant. Patch to n8n 1.123.67, 2.31.5, or 2.32.1, and until then validate or coerce email body fields to strings before they reach the Send Email node in any workflow reachable from an unauthenticated trigger.

Is CVE-2026-72766 actively exploited?

No confirmed active exploitation of CVE-2026-72766 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-72766?

Patch immediately: upgrade to n8n 1.123.67 (1.x line), 2.31.5 (2.x line), or 2.32.1 (2.32.x line) — all affected release lines have fixed versions. Until patched, audit all active workflows for the vulnerable pattern: an unauthenticated webhook trigger feeding a Send Email node with SMTP credentials configured, where the text/HTML body is built from an expression referencing webhook or trigger data instead of a static string. Where found, either disable or authenticate the webhook, or explicitly cast/validate the body field to a string before deployment. For detection, monitor SMTP/outbound logs for anomalous local file paths or unexpected internal/metadata IP addresses appearing in message content, and audit `.env`/credential files for signs of exfiltration if a vulnerable workflow was internet-facing. Restrict outbound network access (egress filtering) from the n8n host as defense-in-depth against the SSRF component.

What systems are affected by CVE-2026-72766?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, AI workflow orchestration, webhook-triggered automation pipelines, notification/alerting integrations.

What is the CVSS score for CVE-2026-72766?

CVE-2026-72766 has a CVSS v3.1 base score of 7.5 (HIGH). The EPSS exploitation probability is 0.44%.

What is the AI security impact?

Affected AI Architectures

agent frameworksAI workflow orchestrationwebhook-triggered automation pipelinesnotification/alerting integrations

MITRE ATLAS Techniques

AML.T0025 Exfiltration via Cyber Means
AML.T0049 Exploit Public-Facing Application

Compliance Controls Affected

ISO 42001: A.6.2.6
NIST AI RMF: MANAGE-4.1
OWASP LLM Top 10: LLM07

What are the technical details?

Original Advisory

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF). Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the node, and untrusted input mapped directly into the body field; this is not a default configuration.

Exploitation Scenario

An organization uses n8n as an AI agent orchestration layer: a public-facing chatbot or contact form triggers an unauthenticated n8n webhook, which runs a workflow that summarizes the incoming request and emails an internal team via the Send Email node using pre-configured SMTP credentials — with the email's HTML body built directly from an expression referencing the webhook payload for convenience. An attacker submits a crafted request where the field n8n resolves as the email body is not a plain string but a specially structured value; Nodemailer misinterprets it as a local file path or a URL rather than literal message content. Depending on which field is manipulated, the attacker either exfiltrates arbitrary files from the n8n host filesystem (e.g., `.env` secrets, SSH keys) through the resulting email, or coerces the n8n server into making outbound requests to internal-only endpoints or the cloud metadata service (SSRF), potentially harvesting cloud credentials. Because the workflow still appears to function normally — an email is sent — the attack can go unnoticed unless SMTP or outbound traffic is actively monitored.

Weaknesses (CWE)

CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion'): The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Timeline

Published
August 11, 2026
Last Modified
August 28, 2026
First Seen
August 11, 2026

Related Vulnerabilities