CVE-2026-33713: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33713 is a SQL injection vulnerability in the n8n open-source workflow automation platform, specifically in the Data Table Get node via the orderByColumn expression parameter. It affects n8n versions prior to 1.123.26, versions 2.0.0-rc.0 through 2.13.2, and version 2.14.0. The vulnerability was published on March 25, 2026, with patches released the same day. It carries a CVSS v4.0 base score of 8.7 (High) and a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is improper neutralization of special elements in an SQL command (CWE-89), where the orderByColumn parameter in the Data Table Get node is not properly sanitized before being incorporated into SQL queries. An authenticated attacker with workflow creation or modification permissions can inject malicious SQL via an expression that incorporates external or user-supplied input into the orderByColumn field. On default SQLite deployments, exploitation is limited to single-statement manipulation; however, on PostgreSQL deployments, multi-statement execution is possible, significantly expanding the attack surface. No public proof-of-concept code has been identified at this time (n8n Security Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the underlying database. On PostgreSQL deployments, this enables data modification, deletion, and potential exfiltration of sensitive information stored in the n8n database, resulting in high confidentiality, integrity, and availability impact. On SQLite (the default backend), the impact is more constrained due to single-statement execution limits, but data manipulation remains possible. The vulnerability does not affect systems subsequent to the vulnerable n8n instance (n8n Security Advisory, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.014–0.023%, placing it in the lower percentiles for near-term exploitation likelihood. Exploitation requires authenticated access with workflow creation or modification permissions, which limits the attack surface compared to unauthenticated vulnerabilities. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, n8n Security Advisory).

Exploitation steps

  1. Gain authenticated access: Obtain credentials for an n8n account with workflow creation or modification permissions — this could be via a low-privilege user account, a compromised credential, or a self-registered account on an open n8n instance.
  2. Identify a vulnerable instance: Confirm the target is running a vulnerable n8n version (< 1.123.26, 2.0.0-rc.0 to < 2.13.3, or = 2.14.0) and uses a Data Table Get node in its workflows.
  3. Create or modify a workflow: Navigate to the n8n workflow editor and create or edit a workflow that includes a Data Table Get node.
  4. Inject malicious SQL via orderByColumn: Set the orderByColumn parameter to an expression that incorporates user-controlled or external input containing SQL injection payloads. For example, on PostgreSQL, craft a multi-statement payload such as legitimate_column; DROP TABLE sensitive_data; -- or a data-exfiltration query.
  5. Execute the workflow: Trigger the workflow execution, causing n8n to pass the unsanitized orderByColumn value directly into the SQL query sent to the backend database.
  6. Achieve objective: On PostgreSQL, retrieve, modify, or delete database records. On SQLite, manipulate the single-statement query to extract or alter data within the constraints of single-statement execution (n8n Security Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: n8n application logs showing unexpected or malformed SQL queries originating from Data Table Get node executions; database error logs (especially PostgreSQL) reflecting SQL syntax errors or multi-statement execution attempts.
  • Database: Unexpected modifications, deletions, or new entries in database tables not attributable to normal workflow activity; evidence of unauthorized DROP, INSERT, UPDATE, or SELECT statements in database query logs.
  • Application: Workflows containing Data Table Get nodes where the orderByColumn field is set to an expression referencing external or user-supplied input, particularly those with SQL metacharacters (;, --, ', UNION, etc.).
  • Network: Unusual outbound connections from the n8n server to external hosts following workflow execution, which may indicate data exfiltration attempts on PostgreSQL deployments.

Mitigation and workarounds

Upgrade n8n to one of the patched versions: 1.123.26, 2.13.3, or 2.14.1 (or later). If immediate upgrade is not possible, administrators should apply the following temporary mitigations: (1) restrict workflow creation and editing permissions to fully trusted users only; (2) disable the Data Table node by adding n8n-nodes-base.dataTable to the NODES_EXCLUDE environment variable; and (3) audit existing workflows for Data Table Get nodes where orderByColumn is set to an expression incorporating external or user-supplied input. Note that these workarounds do not fully remediate the risk and should only be used as short-term measures pending upgrade (n8n Security Advisory, GitHub Advisory).

Community reactions

The Belgian Centre for Cybersecurity (CCB) issued an advisory warning about critical vulnerabilities in n8n and urged immediate patching (CCB Advisory). The vulnerability was credited to researcher "CodeByMoriarty" in the official GitHub advisory. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability tracking and aggregation sites.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management