n8n versions before 1.123.69 contain a server-side...
Moderate severity
Unreviewed
Published
Aug 20, 2026
to the GitHub Advisory Database
•
Updated Sep 1, 2026
Description
Published by the National Vulnerability Database
Aug 20, 2026
Published to the GitHub Advisory Database
Aug 20, 2026
Last updated
Sep 1, 2026
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.
References