← Späť na vyhľadávanie CVE

CVE-2026-59257

n8n

Popis

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node-s executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL string without parameterization. When a workflow uses this operation with expression-sourced values and is connected to an externally-reachable trigger (such as a Webhook node), attacker-controlled input reaching those expressions results in SQL injection, allowing execution of arbitrary SQL with the configured MySQL credentials- privileges. The MySQL v2 node, which uses parameterized queries, is not affected.

CVSS 8.8EPSS 0.314%Riziko 0.9
Zobraziť zdroj
Zverejnené
2026-07-08 14:17:20
Dotknuté verzie
<1.123.61, <2.27.4, <2.28.1
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H