PT-2026-50176 · Postgresql Global Development Group+2 · Postgres+2

·

CVE-2026-54310

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.25.7 n8n versions prior to 2.26.2
Description An authenticated user with permissions to create or modify workflows can provide crafted parameters to the TimescaleDB and legacy Postgres v1 nodes. This allows arbitrary SQL injection and execution against the connected database, operating under the privileges of the configured database account.
Recommendations Update to version 2.25.7 or later. Update to version 2.26.2 or later. Limit workflow creation and editing permissions to fully trusted users only. Disable the Postgres and TimescaleDB nodes by adding n8n-nodes-base.postgres and n8n-nodes-base.timescaleDb to the NODES EXCLUDE environment variable.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54310
GHSA-C37G-W77Q-M4VP

Affected Products

Postgres
Timescaledb
N8N