PT-2026-36907 · N8N · N8N

Jubke

·

Published

2026-04-22

·

Updated

2026-05-05

·

CVE-2026-42237

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.32 n8n versions prior to 2.17.4 n8n versions prior to 2.18.1
Description An open source workflow automation platform contains an issue where the Snowflake node and the legacy MySQL v1 node construct SQL queries by directly interpolating user-controlled table names, column names, and update keys into query strings without identifier escaping. This allows for SQL injection against the connected database.
Recommendations Update to version 1.123.32. Update to version 2.17.4. Update to version 2.18.1.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-06925
CVE-2026-42237
GHSA-HP3C-VFPM-Q4F7

Affected Products

N8N