n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
GHSA-q7m3-rhxg-7vxr · CVE-2026-54687
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Affected versions
< 1.0.0
Patched version
1.0.0
Description
In versions prior to 1.0.0, the SQLite node accepted the database file
path as a direct node parameter visible and editable in the workflow.
A workflow author who mapped untrusted user input to the db_path field
could allow an attacker to control which file was opened by SQLite,
potentially enabling path traversal to read or overwrite arbitrary
files accessible to the n8n process.
The vulnerability requires the workflow author to explicitly wire
untrusted input to the db_path parameter, so it does not affect
standalone deployments where only trusted users author workflows.
However, in multi-tenant or user-facing n8n deployments the risk
is elevated.
Fixed in v1.0.0 by moving the database path into a credential
(v2 node architecture), which is stored server-side and not
controllable by workflow input data.
References
- Fix commit: 145a887
- Introduced credential-based path: v2 node
Credits
dyingman1 (role: Reporter)
References
- WEB https://github.com/DangerBlack/n8n-node-sqlite3/security/advisories/GHSA-q7m3-rhxg-7vxr
- WEB https://github.com/DangerBlack/n8n-node-sqlite3/pull/25
- WEB https://github.com/DangerBlack/n8n-node-sqlite3/commit/145a8876ff12375813bdcd4ae4fe78f460c53a98
- PACKAGE https://github.com/DangerBlack/n8n-node-sqlite3
Ready to move
Start Securing
Free, no credit card | First findings in minutes