Impact
The vulnerability is an SQL injection flaw in the Oracle Database node’s Delete Table Drop operation. By inserting single quotes into the table or schema fields, an attacker can append arbitrary SQL, allowing execution of any DDL or DML with the credentials that the n8n instance is using. The attacker could therefore delete tables, modify data, or create new tables, resulting in data loss, corruption, or exposure.
Affected Systems
The flaw affects n8n versions prior to 1.123.80, any 2.x build before 2.39.6, and the 2.40.0 series before 2.40.1. The affected product is n8n-io:n8n. Users running these releases with an Oracle Database node that has the Delete Table Drop option enabled are vulnerable.
Risk and Exploitability
The CVSS score of 7 classifies the bug as high severity. The EPSS score is not available, but the absence of a KEV listing indicates no publicly confirmed exploitation yet. Attackers would need to access the workflow configuration or trigger the node, so the attack vector is likely authenticated or local. If the database credential is high privileged, the impact could be substantial. Therefore, the risk remains significant until a patch is applied.
OpenCVE Enrichment