Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-54687

n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
Back to all
CVE

CVE-2026-54687

n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)

Affected versions

< 1.0.0

Patched version

1.0.0

Description

In versions prior to 1.0.0, the SQLite node accepted the database file

path as a direct node parameter visible and editable in the workflow.

A workflow author who mapped untrusted user input to the db_path field

could allow an attacker to control which file was opened by SQLite,

potentially enabling path traversal to read or overwrite arbitrary

files accessible to the n8n process.

The vulnerability requires the workflow author to explicitly wire

untrusted input to the db_path parameter, so it does not affect

standalone deployments where only trusted users author workflows.

However, in multi-tenant or user-facing n8n deployments the risk

is elevated.

Fixed in v1.0.0 by moving the database path into a credential

(v2 node architecture), which is stored server-side and not

controllable by workflow input data.

References

  • Fix commit: 145a887
  • Introduced credential-based path: v2 node

Credits

dyingman1 (role: Reporter)

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
6.1
-
4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/DangerBlack/n8n-node-sqlite3/security/advisories/GHSA-q7m3-rhxg-7vxr, https://github.com/DangerBlack/n8n-node-sqlite3/pull/25, https://github.com/DangerBlack/n8n-node-sqlite3/commit/145a8876ff12375813bdcd4ae4fe78f460c53a98, https://github.com/DangerBlack/n8n-node-sqlite3

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00585%
EPSS Percentile
0.46261%
Introduced Version
0
Fix Available
1.0.0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading