PT-2026-40936 · Root+4 · @Rootio/N8N+1
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.43
n8n versions prior to 2.20.7
n8n versions prior to 2.22.1
Description
An attacker with write access to a git repository connected to an n8n Source Control configuration can commit a malicious Data Table JSON file containing a crafted column name. When an administrator performs a Source Control Pull, the application imports the file, which can lead to SQL injection on the internal PostgreSQL instance. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution. This issue requires the instance to use PostgreSQL as its database backend, the Source Control feature to be enabled and connected to a repository the attacker can write to, and an administrator to trigger the Source Control Pull.
Recommendations
Update to version 1.123.43 or later.
Update to version 2.20.7 or later.
Update to version 2.22.1 or later.
Disable the Source Control feature if it is not actively required.
Restrict write access to the connected git repository to fully trusted users only.
Avoid pulling from repositories that may have been modified by untrusted parties.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Rootio/N8N
N8N