SQL Injection Vulnerability in n8n's Snowflake Node Execute Query Operation
CVE-2026-72750

5.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72750?

A SQL injection vulnerability exists in n8n prior to version 1.123.67, 2.31.5, and 2.32.1, specifically within the Snowflake node’s Execute Query operation. This vulnerability arises when workflow authors embed untrusted expression data directly into a SQL query without parameterization, allowing attackers to manipulate the raw SQL query. The recent update addresses this issue by introducing an optional 'Query Parameters' field, enabling developers to safely bind values using positional placeholders, thus enhancing security against SQL injection attacks.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.