Filter Injection Vulnerability in n8n Supabase Node
CVE-2026-103248

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103248?

A filter injection vulnerability exists in the Supabase node's Filters (String) mode of n8n, allowing attackers to exploit untrusted input and inject malicious filter expressions. This exploitation can lead to unauthorized actions such as reading all table rows, updating records, or even deleting entire tables through a single request. Users are advised to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kemrec
.