CVE-2026-103255
Deferred Deferred - Pending Action

Path Traversal in n8n Workflow Supabase Node

Vulnerability report for CVE-2026-103255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security and enabling unauthorized data access and modification.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
n8n n8n to 1.123.80 (exc)
n8n n8n From 2.0.0 (inc) to 2.39.6 (exc)
n8n n8n From 2.40.0 (inc) to 2.40.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103255 is a path traversal and query injection vulnerability in n8n versions before 1.123.80, 2.39.6, and 2.40.1. The Supabase node's tableId parameter is inserted into request paths without validation. Attackers can exploit this by binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security.

Detection Guidance

Check n8n version with 'n8n --version' or inspect package.json. Review Supabase node workflows for tableId parameters bound to untrusted input. Monitor network traffic for suspicious API calls to Supabase Auth or Storage endpoints using the serviceRole key.

Impact Analysis

This vulnerability allows unauthorized data access and modification. Attackers can bypass security controls to read, alter, or delete sensitive data in Supabase databases. It may also enable query injection to manipulate data operations like insert, select, update, delete, and truncate.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to personal or health data. It may result in data breaches, violating confidentiality requirements and triggering regulatory penalties or legal consequences.

Mitigation Strategies
  • Upgrade n8n to patched versions (1.123.80, 2.39.6, or 2.40.1) immediately.
  • Disable the Supabase node in n8n workflows if not required.
  • Rotate the Supabase serviceRole key to invalidate any potential unauthorized access.
  • Restrict access to n8n instances and Supabase APIs to trusted users only.
  • Audit all workflows using the Supabase node for suspicious tableId bindings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart