CVE-2026-33713 Security Alert: HIGH Vulnerability
Urgent: CVE-2026-33713 requires immediate attention.
· 3 min read
```htmlExecutive Summary
A critical SQL injection vulnerability, identified as CVE-2026-33713, has been discovered in the npm n8n automation tool. This vulnerability, rated as HIGH (CVSS 10), allows authenticated users with workflow creation or modification permissions to manipulate SQL queries, potentially leading to data modification and deletion, especially in PostgreSQL deployments. Immediate action is required to protect your applications.
Immediate Action
- Upgrade to
n8n@1.123.26,n8n@2.13.3, orn8n@2.14.1or later to eliminate the vulnerability. - Limit workflow creation and editing permissions to trusted users only.
- Temporarily disable the Data Table node by adding
n8n-nodes-base.dataTableto theNODES_EXCLUDEenvironment variable. - Review existing workflows for any Data Table Get nodes using external or user-supplied input.
- For more information, refer to the vendor advisory [link to vendor advisory].
Affected Versions
npm n8n@<=1.123.25vulnerable; upgrade to1.123.26+npm n8n@<=2.13.2vulnerable; upgrade to2.13.3+npm n8n@<=2.14.0vulnerable; upgrade to2.14.1+
Resolution Guide
To patch your installation, use the following commands:
npm i n8n@1.123.26
npm i n8n@2.13.3
npm i n8n@2.14.1
For temporary mitigation, add the following line to your environment configuration:
NODES_EXCLUDE=n8n-nodes-base.dataTable
To review and modify workflows, ensure that any orderByColumn settings do not incorporate user-supplied input. For example:
if (workflowData.orderByColumn.includes(userInput)) {
throw new Error('Unsafe input detected');
}
Detection & Verification
To check if your installation is vulnerable, run:
npm list n8n
Verify the installed version matches the patched versions. After upgrading, confirm the fix with:
npm list n8n
Risk and Impact
If exploited, this vulnerability can allow unauthorized data manipulation and deletion, leading to severe data integrity issues. The risk is heightened in environments using PostgreSQL, where multi-statement execution can amplify the impact. Protecting your workflows is essential to maintain data security.
```