Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-72750

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 11.3%
CVSS Severity


Contact Us

Shodan ® - All rights reserved