Vulnerability Description
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and executed against the connected database within the privileges of the configured database account. This vulnerability is fixed in 2.25.7 and 2.26.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| N8N | N8N | < 2.25.7 |
Related Weaknesses (CWE)
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-c37g-w77q-m4vpMitigationVendor Advisory
FAQ
What is CVE-2026-54310?
CVE-2026-54310 is a vulnerability with a CVSS score of 9.9 (CRITICAL). n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB...
How severe is CVE-2026-54310?
CVE-2026-54310 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-54310?
Check the references section above for vendor advisories and patch information. Affected products include: N8N N8N.