A critical SQL injection vulnerability has been identified in the n8n workflow automation platform, affecting versions prior to 2.25.7 and 2.26.2. Authenticated users with permissions to create or modify workflows can exploit this vulnerability by supplying crafted parameters to the TimescaleDB and legacy Postgres v1 nodes. This allows arbitrary SQL commands to be executed against the connected database using the privileges of the configured database account. The risk level is critical, as this could lead to unauthorized data access, modification, or deletion. Organizations using n8n with these vulnerable versions are strongly advised to upgrade to the patched versions (2.25.7 or 2.26.2) immediately. This vulnerability is addressed in the latest releases, and no workarounds are available. Users should ensure that all database access permissions are reviewed and minimized to reduce potential impact.
CRITICAL
CVSS 9.9
CVE-2026-54310
2026-08-22
Critical SQL Injection Vulnerability in n8n (CVE-2026-54310)
A critical SQL injection vulnerability in n8n allows authenticated users to execute arbitrary SQL commands. Affected versions are prior to 2.25.7 and 2.26.2. Users are advised to upgrade to the patched versions.