CVE-2026-56351

HIGH
8.2CVSS v3
CVSS v2
0.22% EPSS (exploit probability)
CWE-89CWE

Description

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.

CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references