SQL injection in n8n - #VU140991

 

SQL injection in n8n - #VU140991

Published: August 5, 2026


Vulnerability identifier: #VU140991
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information, modify data, or delete data.

The vulnerability exists due to improper neutralization of special elements in PostgREST filter queries in the Supabase node Row Get Many, Delete, and Update operations when building filter queries with expression-bindable values. A remote attacker can inject a crafted condition to disclose sensitive information, modify data, or delete data.

Exploitation can widen an intended single-row operation to affect every row.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.69, 2.33.4, 2.34.1

External References

Related Security Bulletins