HIGH 7.0 NVD
CVE-2026-103253
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delet
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges.
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-4wf3-rgqr-xcp3
- https://www.vulncheck.com/advisories/n8n-before-1.123.80-2.39.6-and-2.40.1-sql-injection-v
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.