Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters by breaking out of query literals. Attackers can exploit this by binding vulnerable node parameters to untrusted external input to widen single-record lookups into match-all queries, exposing bulk data including contact lists, tickets, and directory entries.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Immediate Patch
AI Analysis

Impact

n8n prior to 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation flaw in SendGrid, Freshservice, and ServiceNow nodes that lets an attacker break out of query literals. The flaw permits filter bypass, turning single‑lookups into match‑all queries which can expose bulk data such as contact lists, tickets, and directory entries.

Affected Systems

Vendor n8n‑io, product n8n. Affected versions include any release before 2.39.6 and any 2.40.0 before 2.40.1.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. EPSS is not available and the vulnerability is not in the CISA KEV catalog. Attackers can exploit the flaw by binding node parameters to untrusted external data; if the node is reachable over the network and the input is not sanitized, they may gain access to sensitive bulk data. The attack likely requires some level of access to configure or trigger a workflow that uses the vulnerable nodes.

Generated by OpenCVE AI on October 1, 2026 at 14:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 2.39.6 or later, or 2.40.1 or later.
  • Remove or disable SendGrid, Freshservice, and ServiceNow nodes from workflows that receive untrusted input.
  • Validate and sanitize all external inputs used in node parameters to eliminate interpolation characters before they are processed.

Generated by OpenCVE AI on October 1, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters by breaking out of query literals. Attackers can exploit this by binding vulnerable node parameters to untrusted external input to widen single-record lookups into match-all queries, exposing bulk data including contact lists, tickets, and directory entries.
Title n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation
First Time appeared N8n
N8n n8n
Weaknesses CWE-943
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:02.133Z

Reserved: 2026-09-30T10:55:39.869Z

Link: CVE-2026-103258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:20.293

Modified: 2026-10-01T11:17:20.420

Link: CVE-2026-103258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic