SQL injection in n8n - #VU140991
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information, modify data, or delete data.
The vulnerability exists due to improper neutralization of special elements in PostgREST filter queries in the Supabase node Row Get Many, Delete, and Update operations when building filter queries with expression-bindable values. A remote attacker can inject a crafted condition to disclose sensitive information, modify data, or delete data.
Exploitation can widen an intended single-row operation to affect every row.