Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Database Data Manipulation and Disclosure
Action: Immediate Patch
AI Analysis

Impact

n8n versions before 1.123.80, 2.39.6 and 2.40.1 contain a filter injection flaw in the Supabase node’s Filters (String) mode. The node fails to escape field values, so an attacker can craft filter expressions that execute arbitrary SQL logic. This allows direct reads of all table rows, updates of all records, or even deletion of entire tables in a single request, effectively giving the attacker full control over the underlying database content.

Affected Systems

The vulnerability affects the n8n workflow automation platform, specifically versions older than 1.123.80, 2.39.6 and 2.40.1. Users running these releases are exposed if they employ the Supabase node with the vulnerable Filters (String) mode.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity, and while an EPSS score is not available, the lack of a KEV listing does not preclude exploitation. Based on the description, the likely attack vector is a remote request that supplies untrusted input to the Supabase node’s filter field, which then allows injection of malicious SQL statements to read, modify or delete database contents.

Generated by OpenCVE AI on October 1, 2026 at 14:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.80 or later, 2.39.6 or 2.40.1, where the injection vulnerability is fixed.
  • When using the Supabase node, avoid the Filters (String) mode or ensure that the filter string is strictly validated and sanitized before use.
  • Restrict workflow access so that only trusted users can define or modify Supabase filters, and audit existing workflows for potential exploitable filter expressions.

Generated by OpenCVE AI on October 1, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase
First Time appeared N8n
N8n n8n
Weaknesses CWE-89
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:26:45.671Z

Reserved: 2026-09-30T10:52:32.248Z

Link: CVE-2026-103248

cve-icon Vulnrichment

Updated: 2026-10-01T13:26:41.219Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:18.257

Modified: 2026-10-01T14:17:20.880

Link: CVE-2026-103248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')