<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>N8n (&lt; 2.39.6, 2.40.0 &lt;= 2.40.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/n8n--2.39.6-2.40.0--2.40.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 12:41:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/n8n--2.39.6-2.40.0--2.40.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Filter Injection Vulnerability in n8n Supabase Node</title><link>https://feed.craftedsignal.io/briefs/2026-10-n8n-supabase-injection/</link><pubDate>Thu, 01 Oct 2026 12:41:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-n8n-supabase-injection/</guid><description>A filter injection vulnerability in the n8n Supabase node (CVE-2026-103248) allows attackers to perform unauthorized data exfiltration, modification, or deletion by injecting malicious filter expressions.</description><content:encoded><![CDATA[<p>n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability within the Supabase node when operating in 'Filters (String)' mode. The vulnerability stems from the application's failure to properly escape or sanitize field values before constructing database queries. This flaw enables unauthenticated attackers to manipulate query logic by injecting arbitrary filter expressions. If successfully exploited, an attacker can bypass intended access controls to read, update, or delete records from the connected Supabase database, potentially leading to total data loss or unauthorized disclosure. Organizations running self-hosted n8n instances with Supabase integrations are advised to update to the patched versions immediately to mitigate the risk of unauthorized database operations.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability can lead to critical data integrity and confidentiality failures. Attackers can perform unauthorized CRUD (Create, Read, Update, Delete) operations on Supabase table rows. Depending on the database configuration and connected services, this could result in mass exfiltration of sensitive information, accidental or malicious destruction of production data, or manipulation of business logic executed via n8n workflows.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade n8n instances to versions 1.123.80, 2.39.6, or 2.40.1 or higher as specified by the vendor security advisory.</li>
<li>Review Supabase node configurations in existing workflows to ensure that inputs mapped to filters are treated as untrusted and properly validated by downstream workflow logic.</li>
<li>Patch CVE-2026-103248 on all self-hosted n8n instances immediately.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>injection</category><category>vulnerability</category><category>n8n</category><category>database</category><category>credential-access</category><category>credentials-leak</category></item></channel></rss>