Input validation error in n8n - #VU139106

 

Input validation error in n8n - #VU139106

Published: July 22, 2026


Vulnerability identifier: #VU139106
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: n8n
Affected software:
n8n

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in the Send Email node message body handling when processing untrusted workflow expression values in the text or HTML body field. A remote attacker can supply a specially crafted non-string value to disclose sensitive information.

Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the Send Email node, and untrusted input mapped directly into the text or HTML body field.


Remediation

Install security update from vendor's website.

Sources