MEDIUMVulnerability
CVE-2026-77074
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.
Properties
- severity
- MEDIUM
- score
- 6.5
- epss_score
- 0.00211
- cve_id
- CVE-2026-77074
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-08-20T12:16:38.740
- last_modified
- 2026-09-01T19:34:40.490
- epss_percentile
- 0.11218
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Control of Generation of Code ('Code Injection')
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (2)
→[Product]
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph