Impact
The flaw allows an attacker who can supply untrusted data to the db_path parameter to perform path traversal beyond the intended SQLite database directory. This can let the attacker read, create, or overwrite arbitrary files that the n8n process can access, potentially exposing sensitive data or altering system files and compromising the integrity of the host. The weakness is a classic input‑validation flaw, categorized as CWE‑22.
Affected Systems
Vendor DangerBlack provides the vulnerable package n8n-node-sqlite3. Any installation of this node before version 1.0.0 is affected, as the node parameter db_path is exposed in the SqliteV1 node implementation. The issue was fixed in version 1.0.0, so installs of 1.0.0 or later are not impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.1, indicating medium severity. EPSS information is currently unavailable, and the advisory does not list it in the CISA KEV catalog. The likely attack vector requires that an attacker be able to inject untrusted input into the workflow that controls db_path; this could happen if the workflow is exposed to external users and does not adequately sanitize input. Successful exploitation would enable an attacker to read or modify any file the n8n process can reach, which can lead to data exfiltration, tampering, or the creation of malicious files.
OpenCVE Enrichment
Github GHSA