PostgREST Filter Injection Vulnerability in n8n by n8n-io
CVE-2026-77071
7.1HIGH
What is CVE-2026-77071?
The n8n automation platform is affected by a PostgREST filter injection vulnerability that allows attackers to manipulate filter queries used in the Supabase node's Row Get Many, Delete, and Update operations. By exploiting this flaw, an attacker could craft such filters that expand the intended scope of these operations, potentially leading to unauthorized access, deletion, or modification of the entire dataset instead of the anticipated single-row operation. This risk highlights the importance of proper input validation and escaping in query construction.
Affected Version(s)
n8n 0 < 1.123.69
n8n 2.34.0 < 2.34.1
n8n 2.0.0 < 2.33.4
