UNKNOWN npm

n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)

GHSA-q7m3-rhxg-7vxr · CVE-2026-54687

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Affected versions

< 1.0.0

Patched version

1.0.0

Description

In versions prior to 1.0.0, the SQLite node accepted the database file
path as a direct node parameter visible and editable in the workflow.
A workflow author who mapped untrusted user input to the db_path field
could allow an attacker to control which file was opened by SQLite,
potentially enabling path traversal to read or overwrite arbitrary
files accessible to the n8n process.

The vulnerability requires the workflow author to explicitly wire
untrusted input to the db_path parameter, so it does not affect
standalone deployments where only trusted users author workflows.
However, in multi-tenant or user-facing n8n deployments the risk
is elevated.

Fixed in v1.0.0 by moving the database path into a credential
(v2 node architecture), which is stored server-side and not
controllable by workflow input data.

References

  • Fix commit: 145a887
  • Introduced credential-based path: v2 node

Credits

dyingman1 (role: Reporter)

Ready to move

Start Securing

Free, no credit card | First findings in minutes