Vulnerability Description
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.
Related Weaknesses (CWE)
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-233r-fpgw-fx8x
- https://www.vulncheck.com/advisories/n8n-before-ssrf-via-edit-image-node
FAQ
What is CVE-2026-77074?
CVE-2026-77074 is a documented vulnerability. n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can cr...
How severe is CVE-2026-77074?
CVSS scoring is not yet available for CVE-2026-77074. Check NVD for updates.
Is there a patch for CVE-2026-77074?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.