CVE-2026-54310 Security Alert: MEDIUM Vulnerability
Urgent: CVE-2026-54310 requires immediate attention.
· 6 min read
Executive Summary
CVE-2026-54310 is a high-risk SQL injection flaw in n8n affecting the TimescaleDB and legacy Postgres v1 nodes. An authenticated user who can create or edit workflows may inject arbitrary SQL into the connected database, executing commands with the privileges of the configured database account. For solo developers and small teams, this can quickly become a full data breach, data loss, or lateral movement issue if the database user is over-privileged.
The issue is fixed in n8n 2.25.7 and 2.26.2. If you cannot upgrade immediately, restrict workflow editing to fully trusted users and temporarily disable the affected nodes. See the vendor advisory: TODO: n8n security advisory.
Immediate Action
- Upgrade now to
n8n@2.25.7orn8n@2.26.2(or later) as soon as possible. - Lock down workflow permissions: only fully trusted users should be able to create or modify workflows until patched.
- Disable vulnerable nodes by setting
NODES_EXCLUDE=n8n-nodes-base.postgres,n8n-nodes-base.timescaleDbif you must delay patching. - Review database privileges: ensure the n8n database account cannot drop schemas, create superusers, or access unrelated databases.
- Consider isolation: if the instance is exposed to multiple users, temporarily isolate it behind VPN/SSO or take it offline for maintenance.
- Back up first and verify you can roll back the application container/package if the upgrade causes issues.
Affected Versions
npm:n8nvulnerable in versions before 2.25.7 and before 2.26.2 depending on release line.npm:n8nsafe versions: 2.25.7+ and 2.26.2+.- Affected components:
n8n-nodes-base.postgresandn8n-nodes-base.timescaleDb. - If you pin Docker images or deploy from source, treat any build older than the fixed tags above as vulnerable.
Resolution Guide
npm / yarn / pnpm
# npm
npm install n8n@2.26.2
# yarn
yarn add n8n@2.26.2
# pnpm
pnpm add n8n@2.26.2
Python ecosystems are not applicable here because the affected product is a Node.js application. If you wrap n8n in a Python-managed deployment, update the underlying service package/container instead.
Maven / Gradle are not applicable to this package directly. If your platform embeds n8n as a service, update the service image or Node.js dependency rather than a Java artifact.
apt / yum are not the primary distribution path for n8n, but if you installed via a system package or custom repo, update to the vendor-provided fixed build:
# apt (example placeholder)
sudo apt-get update
sudo apt-get install n8n=2.26.2-1
# yum/dnf (example placeholder)
sudo dnf upgrade n8n-2.26.2
Docker
# Pull a fixed tag
docker pull n8nio/n8n:2.26.2
# Example compose override
services:
n8n:
image: n8nio/n8n:2.26.2
Temporary hardening
# Disable vulnerable nodes until patched
export NODES_EXCLUDE="n8n-nodes-base.postgres,n8n-nodes-base.timescaleDb"
# Example Docker Compose
environment:
- NODES_EXCLUDE=n8n-nodes-base.postgres,n8n-nodes-base.timescaleDb
Minimal code/config fix example if you maintain a custom workflow wrapper: reject untrusted SQL-like parameters before they reach the node.
// Example guard: block suspicious SQL fragments in user-controlled fields
function isSafeParam(value) {
return typeof value === 'string' && !/[;'"`]|(--|\/\*)|(\bunion\b|\bdrop\b|\bdelete\b|\binsert\b)/i.test(value);
}
if (!isSafeParam(userInput)) {
throw new Error('Unsafe database parameter blocked');
}
Detection & Verification
Check your installed version
n8n --version
npm ls n8n
docker image inspect n8nio/n8n:2.26.2 --format '{{.RepoTags}}'
Search for affected nodes in workflows
grep -R "n8n-nodes-base.postgres\|n8n-nodes-base.timescaleDb" /path/to/n8n/data /path/to/workflows 2>/dev/null
Check whether the workaround is active
echo "$NODES_EXCLUDE"
Verify the fix
# Confirm patched version
n8n --version
# If using Docker, confirm the running image tag
docker ps --format '{{.Image}}' | grep n8n
# Confirm vulnerable nodes are excluded if you used the workaround
node -e "console.log(process.env.NODES_EXCLUDE || '')"
Dependency audit
npm audit --production
npm ls n8n
Risk and Impact
This flaw lets an authenticated workflow editor turn a database node into an SQL injection path. In practice, that can expose tables, modify records, delete data, or run database commands beyond what the workflow author should be allowed to do. The blast radius depends on the database account behind n8n: weakly scoped credentials may mean a full database compromise, while tightly scoped credentials reduce but do not eliminate the risk.
Even though there is no known active exploitation and it is not in CISA KEV, the combination of authenticated access plus arbitrary SQL execution makes this urgent for small teams that share n8n across multiple users or connect it to production databases.