SQL injection in n8n - #VU152998
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL against the connected database with the stored credential's privileges.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in version 1 of the Microsoft SQL node when resolving expressions in the Query field. A remote attacker can supply untrusted input that is interpolated into the SQL query to execute arbitrary SQL against the connected database with the stored credential's privileges.
Exploitation requires a workflow that binds untrusted input to the Query field.