SQL injection in n8n - #VU127224
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in the Oracle Database node Limit field when processing user-controlled expressions in the select operation. A remote user can supply a specially crafted expression value to disclose sensitive information.
Exploitation requires a workflow configuration in which external input is passed into the Limit field, such as through a webhook.