CVE-2026-85170
Received Received - Intake

Remote File Read and SSRF in n8n via Gmail and Brevo Nodes

Vulnerability report for CVE-2026-85170, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
n8n n8n to 1.123.73 (exc)
n8n n8n 2.35.4
n8n n8n 2.36.2
n8n-io n8n to 1.123.73 (exc)
n8n-io n8n to 2.35.4 (exc)
n8n-io n8n to 2.36.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects n8n versions before 1.123.73, 2.35.4, and 2.36.2. It involves the Gmail and Brevo nodes passing message content without verifying it is a string. An authenticated user can exploit this by supplying an expression that resolves to an object with a path or href property, leading to local file access or SSRF attacks.

Impact Analysis

An attacker could read sensitive local files on the n8n server or fetch internal URLs, potentially exposing confidential data. This could lead to data breaches, unauthorized access, or further network compromise depending on the n8n deployment environment.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data or HIPAA by leaking protected health information if local files or internal systems contain such data. Compliance risks include unauthorized data access, insufficient security measures, and potential regulatory penalties.

Mitigation Strategies

Update n8n to a patched version (1.123.73, 2.35.4, or 2.36.2 or later) to address the issue. Review workflows using Gmail or Brevo nodes for suspicious expressions that could resolve to objects with path or href properties.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85170. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart