PT-2026-78927 · Supabase+1 · Supabase+1

·

CVE-2026-77071

·

Published

2026-08-20

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.69 n8n versions prior to 2.33.4 n8n versions prior to 2.34.1
Description A PostgREST filter injection issue exists in the Supabase node during Row Get Many, Delete, and Update operations. The system constructs filter queries by concatenating expression-bindable values without proper escaping. This allows an attacker to inject conditions that expand the filter to match all rows, potentially resulting in full-table data disclosure, deletion, or modification.
Recommendations Update to version 1.123.69 or later. Update to version 2.33.4 or later. Update to version 2.34.1 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77071
GHSA-F4F3-2G67-4VHM

Affected Products

Supabase
N8N