High severity8.8NVD Advisory· Published Aug 11, 2026· Updated Aug 28, 2026
CVE-2026-72750
CVE-2026-72750
Description
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/n8n-io/n8n/security/advisories/GHSA-652q-gvq3-74qvnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/n8n-before-sql-injection-via-executequery-operationnvdThird Party Advisory
News mentions
1- N8n: 16 Vulnerabilities Including RCE and SQLi Disclosed in Single BatchVypr Intelligence · Aug 11, 2026