PostgREST Filter Injection Vulnerability in n8n by n8n-io
CVE-2026-77071

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77071?

The n8n automation platform is affected by a PostgREST filter injection vulnerability that allows attackers to manipulate filter queries used in the Supabase node's Row Get Many, Delete, and Update operations. By exploiting this flaw, an attacker could craft such filters that expand the intended scope of these operations, potentially leading to unauthorized access, deletion, or modification of the entire dataset instead of the anticipated single-row operation. This risk highlights the importance of proper input validation and escaping in query construction.

Affected Version(s)

n8n 0 < 1.123.69

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tr4ce-ju
.