Unescaped Parameter Interpolation Vulnerability in n8n by n8n.io
CVE-2026-103258
6.9MEDIUM
What is CVE-2026-103258?
The unescaped parameter interpolation vulnerability in n8n affects SendGrid, Freshservice, and ServiceNow nodes in versions prior to 2.39.6 and 2.40.0 before 2.40.1. Attackers can exploit this flaw by supplying untrusted external input to vulnerable node parameters, allowing them to bypass filters and expand single-record lookups into match-all queries. This can potentially expose sensitive information such as contact lists, tickets, and directory entries, posing a significant risk to data security.
Affected Version(s)
n8n 0 < 2.39.6
n8n 2.40.0 < 2.40.1
