CVE-2026-103258
Deferred Deferred - Pending Action

Remote Code Execution in n8n Workflow Automation

Vulnerability report for CVE-2026-103258, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters by breaking out of query literals. Attackers can exploit this by binding vulnerable node parameters to untrusted external input to widen single-record lookups into match-all queries, exposing bulk data including contact lists, tickets, and directory entries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
n8n n8n to 2.39.6 (exc)
n8n n8n to 2.40.0 (exc)
n8n n8n to 2.40.1 (exc)
n8n n8n to 2.39.6|end_excluding=2.40.0 (exc)
sendgrid sendgrid *
freshservice freshservice *
servicenow servicenow *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects n8n versions before 2.39.6 and 2.40.0 before 2.40.1. It involves unescaped parameter interpolation in SendGrid, Freshservice, and ServiceNow nodes. Attackers can bind vulnerable parameters to untrusted input to break out of query literals, converting single-record lookups into match-all queries that expose bulk data like contact lists or tickets.

Detection Guidance

To detect this vulnerability, check the version of n8n installed on your system. If you are running a version before 2.39.6 or 2.40.0 before 2.40.1, your system is vulnerable. Use commands like 'n8n --version' or check your package manager for installed versions.

Impact Analysis

If exploited, this vulnerability could allow attackers to access sensitive bulk data such as contact lists, tickets, or directory entries from connected services. Exploitation requires a workflow configured to bind vulnerable parameters to untrusted input, but no privileges or user interaction are needed.

Mitigation Strategies

Immediately update n8n to version 2.40.1 or 2.39.6 or later. Temporarily restrict access to trusted users only, audit all workflows for vulnerable configurations, and consider deactivating webhook-triggered workflows until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103258. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart