CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103255

CRITICALCVSS 9NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to trave

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103255 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103255

CRITICALCVSS 9NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to trave

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]