CVE-2026-56351Disclosure(n8n / n8n)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 106-24
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - n8n SQL injection via unescaped identifiers in DB workflow nodes (CVE-2026-56351) n8n before 2.4.0 is vulnerable to SQL injection in its MySQL, PostgreSQL, and Microsoft SQL workflow nodes due to improper escaping of identifier values (e.g., table/column names) in node configuration. The root cause is improper input validation/escaping of SQL identifiers, allowing attacker-controlled identifiers to be interpreted as executable SQL. An authenticated user who can create or modify workflows can supply crafted table or column names to inject arbitrary SQL through these nodes and run unauthorized database commands. Impact includes unauthorized data modification/deletion, potential data exposure, and broader compromise of downstream systems relying on the affected database. 👉 Affected: n8n < 2.4.0 | Upgrade to 2.4.0

    Post summary

    The post announces an SQL injection vulnerability (CVE‑2026‑56351) in n8n workflow nodes due to improper identifier escaping, specifies its impact, and notes that the issue is fixed in version 2.4.0.

    0000057
    226 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more