Intel

AIKIDO-2025-10163

n8n-nodes-base is vulnerable to SQL injection

SQL injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 18, 2025

88

High Risk

This Affects:

JSn8n-nodes-base
0.196.0 - 1.83.2
Fixed in 1.84.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to SQL injection when performing table searches in the MySQL Node, due to insufficient input sanitization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the MySql Node.

Background info

n8n-nodes-base is vulnerable to SQL injection in versions 0.196.0 - 1.83.2.

How to fix this

Upgrade the n8n-nodes-base library to the patch version.