PT-2026-70163 · Snowflake+1 · Snowflake+1

CVE-2026-72750

·

Published

2026-07-22

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.67 n8n versions prior to 2.31.5 n8n versions prior to 2.32.1
Description A SQL injection issue exists in the Snowflake node's Execute Query operation. The system interpolates expression values directly into the SQL string without parameterization. If a workflow author embeds untrusted, externally-controlled expression data into a raw SQL query, it allows for SQL injection.
Recommendations Update to version 1.123.67 or later. Update to version 2.31.5 or later. Update to version 2.32.1 or later. Use the 'Query Parameters' field to bind values via positional placeholders instead of embedding expression data directly into raw SQL queries.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72750
GHSA-652Q-GVQ3-74QV

Affected Products

Snowflake
N8N