Impact
n8n versions before 1.123.80, 2.39.6 and 2.40.1 contain a filter injection flaw in the Supabase node’s Filters (String) mode. The node fails to escape field values, so an attacker can craft filter expressions that execute arbitrary SQL logic. This allows direct reads of all table rows, updates of all records, or even deletion of entire tables in a single request, effectively giving the attacker full control over the underlying database content.
Affected Systems
The vulnerability affects the n8n workflow automation platform, specifically versions older than 1.123.80, 2.39.6 and 2.40.1. Users running these releases are exposed if they employ the Supabase node with the vulnerable Filters (String) mode.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, and while an EPSS score is not available, the lack of a KEV listing does not preclude exploitation. Based on the description, the likely attack vector is a remote request that supplies untrusted input to the Supabase node’s filter field, which then allows injection of malicious SQL statements to read, modify or delete database contents.
OpenCVE Enrichment