Back

HIGH

n8n before 1.123.69 PostgREST Filter Injection via Supabase

Published Aug 20, 2026

Description

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intended single-row operation into full-table disclosure, deletion, or modification.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 20, 2026
Updated Aug 21, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Aug 21, 2026
NVD
Status Analyzed
Modified Sep 1, 2026
Red Hat
Severity n/a
Public date n/a