Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security and enabling unauthorized data access and modification.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in the Supabase integration of n8n allows an attacker to inject a tableId parameter without validation, enabling traversal into Auth and Storage APIs that use an administrative serviceRole key. By doing so, the attacker can bypass row‑level security and read, modify, or delete data stored in Supabase. The vulnerability is a classic query injection type flaw, identified by CWE‑73, and provides a means to compromise confidentiality and integrity of data managed by the platform.

Affected Systems

The affected products are n8n by n8n‑io. Vulnerable releases include all versions before 1.123.80 in the 1.x line, all releases prior to 2.39.6 in the 2.0.0 to 2.39.6 range, and all releases prior to 2.40.1 in the 2.40.x line.

Risk and Exploitability

The CVSS score of 7.1 places this among high‑risk vulnerabilities, though the EPSS score is not available and it is not listed in CISA’s KEV catalog. Attackers exploiting this flaw need only control a workflow that supplies an untrusted tableId value; no additional privileges are required beyond the workflow context. Successful exploitation would enable an attacker to traverse to privileged Supabase endpoints and perform unauthorized data operations, potentially resulting in a data breach. The likelihood of exploitation depends on the attacker’s ability to influence workflow parameters and the presence of the compromised administrative key.

Generated by OpenCVE AI on October 1, 2026 at 14:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest n8n patch that removes the unvalidated tableId handling (v1.123.80 or later, v2.39.6 or later, v2.40.1 or later).
  • If an immediate update isn’t possible, restrict workflow configuration so that the tableId parameter cannot be bound to external input; for example, hard‑code acceptable IDs or enforce strict validation.
  • As a temporary measure, block the administrative serviceRole key from the Supabase Project or rotate the key and remove elevated privileges from workflows.

Generated by OpenCVE AI on October 1, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security and enabling unauthorized data access and modification.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase
First Time appeared N8n
N8n n8n
Weaknesses CWE-73
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:00.052Z

Reserved: 2026-09-30T10:55:39.869Z

Link: CVE-2026-103255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:19.717

Modified: 2026-10-01T11:17:19.860

Link: CVE-2026-103255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-73

    External Control of File Name or Path