CVE-2026-42233Disclosure(n8n / n8n)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the Limit field (e.g., from a webhook), an attacker could inject arbitrary SQL and exfiltrate data from the connected Oracle database. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-13)
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-07: 2Mentions · 2026-05-13: 3Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 205-0405-0505-0705-13
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-051
General1
2026-05-072
General1Patch1
2026-05-133
Disclosure2General1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42233 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory n8n is an open source workflow automation platform.

    Post summary

    The post announces CVE-2026-42233 for n8n with a CVSS score of 9.8 (critical severity), providing technical details but no proof of concept, exploit, or patch information.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-42233 · 9.8 → 1.123.32 CVE: CVE-2026-42233 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text is a disclosure of CVE-2026-42233 with a CVSS score of 9.8 and critical severity, but lacks details on exploitation, patches, or PoC.

    1000030
    210 followersView on X
  • ByteGuard@byte_guard_blog
    Patch

    SQL injection in the Oracle Database node allows data exfiltration via the Limit field. CVE-2026-42233, CVSS 9.8. Affects n8n < 1.123.32. Update to 1.123.32, 2.17.4, or 2.18.1. #InfoSec #N8n

    Post summary

    Oracle Database node SQL injection via the Limit field permits data exfiltration (CVE‑2026‑42233). The vulnerability is high severity (CVSS 9.8) and patches are available for n8n versions 1.123.32, 2.17.4, and 2.18.1.

    0001058
    10 followersView on X
  • z3n@zench4n
    General

    The danger lies in autonomous tool integration. Look at recent n8n vulnerabilities like CVE-2026-42233. In an agentic workflow, a single compromised automation node allows an attacker to hijack the entire logic chain. Agents don't just talk; they act on your infrastructure.

    Post summary

    The post briefly mentions a CVE associated with n8n but provides no concrete details on exploitation, technical aspects, or mitigation.

    1000029
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42233 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user… https://www.cve.org/CVERecord?id=CVE-2026-42233

    Post summary

    The post announces CVE-2026-42233 affecting n8n’s Oracle Database node in versions before 1.123.32, 2.17.4, and 2.18.1, but provides no technical details, exploit proofs, or mitigation information.

    00010170
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42233-n8n-n8n #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text does not contain actionable or detailed information about the CVE; it only references a URL and generic tags.

    0000023
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42233 SQL Injection in n8n Oracle Database Node Prior to Versions 1.123.32, 2.17.4, and 2.18.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42233

    Post summary

    The post cites CVE-2026-42233 as a SQL injection flaw in n8n’s Oracle Database node for versions before 1.123.32, 2.17.4, and 2.18.1, but provides no PoC, exploit, or patch information.

    0000033
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.18.0node.js-

Explore more