Path Traversal Vulnerability in n8n Supabase Node
CVE-2026-103255
7.1HIGH
What is CVE-2026-103255?
The Supabase node in n8n versions prior to 1.123.80, from 2.0.0 to 2.39.6, and from 2.40.0 to 2.40.1 is affected by a path traversal vulnerability. This occurs when the tableId parameter is inadequately validated before inclusion in request paths. An attacker exploiting this flaw can leverage workflows that bind the tableId to data from untrusted input. This exploitation allows unauthorized traversal to critical Auth and Storage APIs, using the administrative serviceRole key, which can bypass Row Level Security controls. Consequently, this leads to unauthorized access and potential modification of sensitive data.
Affected Version(s)
n8n 0 < 1.123.80
n8n 2.0.0 < 2.39.6
n8n 2.40.0 < 2.40.1
