CVE-2026-72766: n8n: Send Email node type confusion enables SSRF, LFI
HIGHn8n's Send Email node fails to enforce that message body fields are strings, letting a crafted non-string value from a workflow expression be misread by the underlying Nodemailer library as a file path or URL — enabling arbitrary local file disclosure or server-side request forgery. The blast radius is real but narrow: exploitation requires a specific combination already present in the target environment — an active workflow with an unauthenticated webhook, SMTP credentials configured on the Send Email node, and untrusted input mapped directly into the body field — so this is not exploitable by default and depends entirely on how a given workflow was built. There's no public exploit code, no Nuclei template, it's absent from CISA KEV, and the EPSS score of 0.28% signals low near-term exploitation probability, consistent with CISA's own SSVC 'Track' decision (monitor, don't scramble). Given n8n's growing footprint as an AI agent orchestration platform where workflows routinely wire external webhook triggers into notification nodes, security teams should still audit existing workflows for this exact webhook-to-SMTP-node pattern rather than assume the missing CVSS score means it's unimportant. Patch to n8n 1.123.67, 2.31.5, or 2.32.1, and until then validate or coerce email body fields to strings before they reach the Send Email node in any workflow reachable from an unauthenticated trigger.
What is the risk?
Overall aggregate risk is low-to-moderate but can be high for specific misconfigured workflows. No CVSS score has been assigned, the vulnerability is absent from CISA KEV, there is no public PoC or Nuclei scanner coverage, and EPSS (0.28%) places it well within the low-probability range for near-term mass exploitation. However, the required preconditions — an unauthenticated webhook trigger, valid SMTP credentials on the Send Email node, and unsanitized input flowing into the body/HTML field — describe a realistic and common automation pattern (e.g., 'form submission triggers a notification email'). Where that pattern exists, impact is significant: arbitrary local file read can expose n8n's `.env`, credentials, or SSH keys, and SSRF can pivot into internal networks or cloud metadata endpoints. CISA's TRACK SSVC decision is appropriate at the ecosystem level, but individual n8n operators exposing webhooks publicly should treat this as urgent, workflow-specific risk rather than a low-priority CVE.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| n8n | npm | — | No patch |
Do you use n8n? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Patch immediately: upgrade to n8n 1.123.67 (1.x line), 2.31.5 (2.x line), or 2.32.1 (2.32.x line) — all affected release lines have fixed versions. Until patched, audit all active workflows for the vulnerable pattern: an unauthenticated webhook trigger feeding a Send Email node with SMTP credentials configured, where the text/HTML body is built from an expression referencing webhook or trigger data instead of a static string. Where found, either disable or authenticate the webhook, or explicitly cast/validate the body field to a string before deployment. For detection, monitor SMTP/outbound logs for anomalous local file paths or unexpected internal/metadata IP addresses appearing in message content, and audit
.env/credential files for signs of exfiltration if a vulnerable workflow was internet-facing. Restrict outbound network access (egress filtering) from the n8n host as defense-in-depth against the SSRF component.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72766?
n8n's Send Email node fails to enforce that message body fields are strings, letting a crafted non-string value from a workflow expression be misread by the underlying Nodemailer library as a file path or URL — enabling arbitrary local file disclosure or server-side request forgery. The blast radius is real but narrow: exploitation requires a specific combination already present in the target environment — an active workflow with an unauthenticated webhook, SMTP credentials configured on the Send Email node, and untrusted input mapped directly into the body field — so this is not exploitable by default and depends entirely on how a given workflow was built. There's no public exploit code, no Nuclei template, it's absent from CISA KEV, and the EPSS score of 0.28% signals low near-term exploitation probability, consistent with CISA's own SSVC 'Track' decision (monitor, don't scramble). Given n8n's growing footprint as an AI agent orchestration platform where workflows routinely wire external webhook triggers into notification nodes, security teams should still audit existing workflows for this exact webhook-to-SMTP-node pattern rather than assume the missing CVSS score means it's unimportant. Patch to n8n 1.123.67, 2.31.5, or 2.32.1, and until then validate or coerce email body fields to strings before they reach the Send Email node in any workflow reachable from an unauthenticated trigger.
Is CVE-2026-72766 actively exploited?
No confirmed active exploitation of CVE-2026-72766 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-72766?
Patch immediately: upgrade to n8n 1.123.67 (1.x line), 2.31.5 (2.x line), or 2.32.1 (2.32.x line) — all affected release lines have fixed versions. Until patched, audit all active workflows for the vulnerable pattern: an unauthenticated webhook trigger feeding a Send Email node with SMTP credentials configured, where the text/HTML body is built from an expression referencing webhook or trigger data instead of a static string. Where found, either disable or authenticate the webhook, or explicitly cast/validate the body field to a string before deployment. For detection, monitor SMTP/outbound logs for anomalous local file paths or unexpected internal/metadata IP addresses appearing in message content, and audit `.env`/credential files for signs of exfiltration if a vulnerable workflow was internet-facing. Restrict outbound network access (egress filtering) from the n8n host as defense-in-depth against the SSRF component.
What systems are affected by CVE-2026-72766?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, AI workflow orchestration, webhook-triggered automation pipelines, notification/alerting integrations.
What is the CVSS score for CVE-2026-72766?
CVE-2026-72766 has a CVSS v3.1 base score of 7.5 (HIGH). The EPSS exploitation probability is 0.44%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0025 Exfiltration via Cyber Means AML.T0049 Exploit Public-Facing Application Compliance Controls Affected
What are the technical details?
Original Advisory
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF). Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the node, and untrusted input mapped directly into the body field; this is not a default configuration.
Exploitation Scenario
An organization uses n8n as an AI agent orchestration layer: a public-facing chatbot or contact form triggers an unauthenticated n8n webhook, which runs a workflow that summarizes the incoming request and emails an internal team via the Send Email node using pre-configured SMTP credentials — with the email's HTML body built directly from an expression referencing the webhook payload for convenience. An attacker submits a crafted request where the field n8n resolves as the email body is not a plain string but a specially structured value; Nodemailer misinterprets it as a local file path or a URL rather than literal message content. Depending on which field is manipulated, the attacker either exfiltrates arbitrary files from the n8n host filesystem (e.g., `.env` secrets, SSH keys) through the resulting email, or coerces the n8n server into making outbound requests to internal-only endpoints or the cloud metadata service (SSRF), potentially harvesting cloud credentials. Because the workflow still appears to function normally — an email is sent — the attack can go unnoticed unless SMTP or outbound traffic is actively monitored.
Weaknesses (CWE)
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
Primary
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion'): The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References
Timeline
Related Vulnerabilities
CVE-2026-33663 10.0 n8n: member role steals plaintext HTTP credentials
Same package: n8n CVE-2026-33660 10.0 TensorFlow: type confusion NPD in tensor conversion
Same package: n8n CVE-2026-21858 10.0 n8n: Input Validation flaw enables exploitation
Same package: n8n CVE-2026-27494 9.9 n8n: security flaw enables exploitation
Same package: n8n CVE-2026-27495 9.9 n8n: Code Injection enables RCE
Same package: n8n