{"id":"CVE-2026-85170","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-85170","summary":"n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user…","details":"n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8n process or fetch an internal URL (SSRF) and attach the result to the outgoing message.","published":"2026-09-03T13:06:24.540","modified":"2026-09-03T13:06:24.540","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-95ph-833c-4wrp"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/n8n-before-1.123.73-local-file-read-and-ssrf-via-gmail-and-brevo-nodes"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T13:06:24.540"}}