PT-2026-70163 · Snowflake+1 · Snowflake+1
CVE-2026-72750
·
Published
2026-07-22
·
Updated
2026-08-28
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.67
n8n versions prior to 2.31.5
n8n versions prior to 2.32.1
Description
A SQL injection issue exists in the Snowflake node's Execute Query operation. The system interpolates expression values directly into the SQL string without parameterization. If a workflow author embeds untrusted, externally-controlled expression data into a raw SQL query, it allows for SQL injection.
Recommendations
Update to version 1.123.67 or later.
Update to version 2.31.5 or later.
Update to version 2.32.1 or later.
Use the 'Query Parameters' field to bind values via positional placeholders instead of embedding expression data directly into raw SQL queries.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snowflake
N8N