Executive brief
n8n is a workflow automation platform that allows users to create and execute automated data processing workflows. An authenticated user with permission to modify workflows can inject SQL commands through the Data Table node's orderByColumn parameter, potentially allowing them to read, modify, or delete data from the underlying database. On PostgreSQL databases, this could result in complete data compromise or service disruption.
Technical details
This vulnerability is a SQL injection flaw in the Data Table Get node's orderByColumn parameter. An authenticated user with workflow creation or modification permissions can craft malicious expressions in the orderByColumn field to inject arbitrary SQL commands. The attack requires authentication and workflow editing permissions. On SQLite (the default database), single-statement injection is possible with limited practical impact. On PostgreSQL deployments, attackers can execute multiple statements, enabling full data modification, deletion, and exfiltration. The vulnerability has been patched in versions 1.123.26, 2.13.3, and 2.14.1.
Affected products
- n8n n8n < 1.123.26, < 2.13.3, < 2.14.1
Timeline
- 2026-03-26: disclosed
- 2026-03-26: patched: Versions 1.123.26, 2.13.3, and 2.14.1 contain patches