What is CVE-2026-72762?
CVE-2026-72762 is an arbitrary file write vulnerability in the Edit Image node of n8n, where the output format parameter is passed to the underlying library without validation. An authenticated user with workflow execution rights can exploit this by supplying a crafted format value to write arbitrary files. Versions before 1.123.67, 2.31.5, and 2.32.1 are affected; immediate upgrade is required.
Azərbaycanca: CVE-2026-72762, n8n avtomatlaşdırma alətində "Edit Image" nodu vasitəsilə özbaşına fayl yazma zəifliyidir. Doğrulanmış istifadəçi, çıxış formatı parametrini təsdiqləmədən ötürərək, xüsusi hazırlanmış dəyərlə ixtiyari fayl yarada bilər. Təsirə məruz qalan versiyalar 1.123.67, 2.31.5 və 2.32.1-dən əvvəlki versiyalardır, dərhal göstərilən versiyalara yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which component of n8n contains the CVE-2026-72762 vulnerability?
The CVE-2026-72762 vulnerability exists in the "Edit Image" node of the n8n automation tool.
To which versions should a system be upgraded to mitigate CVE-2026-72762?
The system should be upgraded to versions 1.123.67, 2.31.5, or 2.32.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.