Path Traversal Vulnerability in n8n Supabase Node
CVE-2026-103255

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103255?

The Supabase node in n8n versions prior to 1.123.80, from 2.0.0 to 2.39.6, and from 2.40.0 to 2.40.1 is affected by a path traversal vulnerability. This occurs when the tableId parameter is inadequately validated before inclusion in request paths. An attacker exploiting this flaw can leverage workflows that bind the tableId to data from untrusted input. This exploitation allows unauthorized traversal to critical Auth and Storage APIs, using the administrative serviceRole key, which can bypass Row Level Security controls. Consequently, this leads to unauthorized access and potential modification of sensitive data.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nora-Qiu
.