SQL Injection Vulnerability in n8n Affected by Improper Parameter Handling
CVE-2026-72775

5.8MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72775?

n8n prior to specific versions is susceptible to SQL injection in its PostgresTrigger node. The vulnerability arises when user-supplied identifiers, such as channel, function, and trigger names, are interpolated directly into SQL statements without sufficient escaping. This flaw can lead to unauthorized execution of arbitrary SQL commands in the context of the connected PostgreSQL database, allowing affected authenticated users to manipulate database content in ways that can compromise data integrity and security.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sm1ee
.