SQL injection in n8n - #VU152998

 

SQL injection in n8n - #VU152998

Published: September 30, 2026


Vulnerability identifier: #VU152998
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL against the connected database with the stored credential's privileges.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in version 1 of the Microsoft SQL node when resolving expressions in the Query field. A remote attacker can supply untrusted input that is interpolated into the SQL query to execute arbitrary SQL against the connected database with the stored credential's privileges.

Exploitation requires a workflow that binds untrusted input to the Query field.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 2.41.4, 2.42.1

External References

Related Security Bulletins