SQL injection in n8n - #VU150765

 

SQL injection in n8n - #VU150765

Published: September 17, 2026


Vulnerability identifier: #VU150765
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify or delete database data.

The vulnerability exists due to SQL injection in the Oracle Database node Delete Table → Drop operation when processing table or schema values bound to untrusted upstream data. A remote attacker can supply crafted values containing SQL to modify or delete database data.

Injected statements execute with the privileges of the connected database credential.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.80, 2.39.6, 2.40.1

External References

Related Security Bulletins