Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3gw-mm62-q9gj

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 8.8

Описание

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.

EPSS

Процентиль: 18%
0.00259
Низкий

5.3 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.

EPSS

Процентиль: 18%
0.00259
Низкий

5.3 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89