CVE WATCH / VULNERABILITY DETAIL
CVE-2026-103258
MEDIUMCVSS 6.8NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters by breaking out of query literals. Attackers can exploit this by binding vulnerable node parameters t
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog