Input validation error in n8n - #VU139106
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the Send Email node message body handling when processing untrusted workflow expression values in the text or HTML body field. A remote attacker can supply a specially crafted non-string value to disclose sensitive information.
Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the Send Email node, and untrusted input mapped directly into the text or HTML body field.