Unescaped Parameter Interpolation Vulnerability in n8n by n8n.io
CVE-2026-103258

6.9MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103258?

The unescaped parameter interpolation vulnerability in n8n affects SendGrid, Freshservice, and ServiceNow nodes in versions prior to 2.39.6 and 2.40.0 before 2.40.1. Attackers can exploit this flaw by supplying untrusted external input to vulnerable node parameters, allowing them to bypass filters and expand single-record lookups into match-all queries. This can potentially expose sensitive information such as contact lists, tickets, and directory entries, posing a significant risk to data security.

Affected Version(s)

n8n 0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DarkLycn1976
.