What is CVE-2026-72766?
This vulnerability occurs due to a type confusion in the 'Send Email' node of the n8n workflow automation tool, where message fields are not enforced as strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can lead to unexpected behavior. Upgrading to the latest patched version is recommended to mitigate the risk.
Azərbaycanca: Bu zəiflik n8n iş axını avtomatlaşdırma alətinin 'Send Email' node'unda type confusion səbəbindən baş verir. İş axını ifadəsindən mətn yerinə xüsusi hazırlanmış qeyri-string dəyər göndərilərsə, bu, e-poçt göndərmə funksiyasında gözlənilməz davranışla nəticələnə bilər. Təsirə məruz qalmamaq üçün n8n versiyasını ən son təhlükəsizlik yeniləməsinə qədər artırmaq tövsiyə olunur.
Related CVEs
link basis: shared vendor: n8n
FAQ2
Which component of n8n is affected by CVE-2026-72766?
This vulnerability affects the 'Send Email' node of the n8n workflow automation tool.
What measure should be taken to mitigate the risk of CVE-2026-72766?
Upgrading to the latest patched version is recommended to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.