CVE-2026-103255: n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security and enabling unauthorized data access and modification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.80 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Which deployments are actually exposed to exploitation?
Affected n8n deployments are exposed when they use the Supabase node in a workflow that binds the tableId parameter to untrusted input. The issue affects versions before 1.123.80, versions from 2.0.0 before 2.39.6, and versions from 2.40.0 before 2.40.1.
What access does an attacker need?
No n8n privileges or user interaction are required according to the supplied vector. The attacker needs a way to provide untrusted input that reaches a Supabase node's tableId parameter in an affected workflow.
What is the practical impact if exploitation succeeds?
An attacker can use path traversal to reach Supabase Auth and Storage APIs with the administrative serviceRole key. This can bypass Row Level Security and allow unauthorized data access and modification.