GHSA-2x35-3fw4-9jr4: n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
Summary
A vulnerability in n8n's Send Email node allowed attackers to read local files or perform SSRF (server-side request forgery, where a server is tricked into making requests to unintended targets) by sending specially crafted non-string values through workflow expressions. The attack required an existing public webhook and untrusted input directly connected to the email body fields.
Solution / Mitigation
The issue has been fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Users should upgrade to one of these versions or later. As temporary workarounds if upgrading is not immediately possible: audit workflows with Send Email nodes that map untrusted data into text or HTML body fields and disable or restrict them; restrict public webhook access at the network or reverse-proxy level (a system that forwards requests); and limit workflow creation and editing permissions to trusted users only. The source notes these workarounds do not fully fix the risk and are only short-term measures.
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://github.com/advisories/GHSA-2x35-3fw4-9jr4
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 75%