{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/n8n--2.39.6-2.40.0--2.40.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2026-103248"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (\u003c 1.123.80, 2.0.0-2.39.5, 2.40.0)","n8n (\u003c 2.39.6, 2.40.0)","n8n (\u003c 1.123.80)","n8n (\u003c 2.39.6, 2.40.0 \u003c= 2.40.1)"],"_cs_severities":["high"],"_cs_tags":["injection","vulnerability","n8n","database","credential-access","credentials-leak"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003en8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability within the Supabase node when operating in 'Filters (String)' mode. The vulnerability stems from the application's failure to properly escape or sanitize field values before constructing database queries. This flaw enables unauthenticated attackers to manipulate query logic by injecting arbitrary filter expressions. If successfully exploited, an attacker can bypass intended access controls to read, update, or delete records from the connected Supabase database, potentially leading to total data loss or unauthorized disclosure. Organizations running self-hosted n8n instances with Supabase integrations are advised to update to the patched versions immediately to mitigate the risk of unauthorized database operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability can lead to critical data integrity and confidentiality failures. Attackers can perform unauthorized CRUD (Create, Read, Update, Delete) operations on Supabase table rows. Depending on the database configuration and connected services, this could result in mass exfiltration of sensitive information, accidental or malicious destruction of production data, or manipulation of business logic executed via n8n workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances to versions 1.123.80, 2.39.6, or 2.40.1 or higher as specified by the vendor security advisory.\u003c/li\u003e\n\u003cli\u003eReview Supabase node configurations in existing workflows to ensure that inputs mapped to filters are treated as untrusted and properly validated by downstream workflow logic.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-103248 on all self-hosted n8n instances immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T12:42:09Z","date_published":"2026-10-01T12:41:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-n8n-supabase-injection/","summary":"A filter injection vulnerability in the n8n Supabase node (CVE-2026-103248) allows attackers to perform unauthorized data exfiltration, modification, or deletion by injecting malicious filter expressions.","title":"Filter Injection Vulnerability in n8n Supabase Node","url":"https://feed.craftedsignal.io/briefs/2026-10-n8n-supabase-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (\u003c 2.39.6, 2.40.0 \u003c= 2.40.1)","version":"https://jsonfeed.org/version/1.1"}