Impact
A path traversal flaw in the Supabase integration of n8n allows an attacker to inject a tableId parameter without validation, enabling traversal into Auth and Storage APIs that use an administrative serviceRole key. By doing so, the attacker can bypass row‑level security and read, modify, or delete data stored in Supabase. The vulnerability is a classic query injection type flaw, identified by CWE‑73, and provides a means to compromise confidentiality and integrity of data managed by the platform.
Affected Systems
The affected products are n8n by n8n‑io. Vulnerable releases include all versions before 1.123.80 in the 1.x line, all releases prior to 2.39.6 in the 2.0.0 to 2.39.6 range, and all releases prior to 2.40.1 in the 2.40.x line.
Risk and Exploitability
The CVSS score of 7.1 places this among high‑risk vulnerabilities, though the EPSS score is not available and it is not listed in CISA’s KEV catalog. Attackers exploiting this flaw need only control a workflow that supplies an untrusted tableId value; no additional privileges are required beyond the workflow context. Successful exploitation would enable an attacker to traverse to privileged Supabase endpoints and perform unauthorized data operations, potentially resulting in a data breach. The likelihood of exploitation depends on the attacker’s ability to influence workflow parameters and the presence of the compromised administrative key.
OpenCVE Enrichment