MEDIUM 6.0 NVD
CVE-2026-77074
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-233r-fpgw-fx8x
- https://www.vulncheck.com/advisories/n8n-before-ssrf-via-edit-image-node
This medium severity vulnerability with a CVSS score of 6.0 was published on 2026-08-20 via NVD.
vulnfeed aggregates 11672 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.