Executive brief
n8n is a workflow automation tool used to connect various software services and databases. A vulnerability in its Snowflake and legacy MySQL connectors allows attackers to inject malicious database commands if the workflow is configured to use external data (like webhooks or forms) to define table or column names. This could lead to unauthorized access, modification, or deletion of sensitive data stored in the connected databases.
Technical details
A SQL injection vulnerability exists in n8n's Snowflake and legacy MySQL v1 nodes. The root cause is the direct interpolation of user-controlled input into SQL query strings for identifiers such as table names, column names, and update keys without proper escaping. An attacker with the ability to trigger a workflow that passes unvalidated input (e.g., via webhooks or forms) into these specific identifier fields can execute arbitrary SQL commands on the downstream database. This can result in full data exfiltration or modification. The issue is fixed in versions 1.123.32, 2.17.4, and 2.18.1. Workarounds include migrating to the MySQL v2 node or excluding the Snowflake node via environment variables.
Affected products
- n8n-io n8n < 1.123.32, >= 2.0.0 < 2.17.4, >= 2.18.0 < 2.18.1
Timeline
- 2026-04-22: disclosed: Initial report/publication by researcher
- 2026-04-29: advisory: GitHub Advisory published
- 2026-05-04: other: NVD publication date