CVE-2026-54310 | n8n-io n8n up to 2.25.6/2.26.1 Parameter sql injection (GHSA-c37g-w77q-m4vp)
A vulnerability categorized as critical has been discovered in n8n-io n8n up to 2.25.6/2.26.1. This affects an unknown part of the component Parameter Handler. Such manipulation leads to sql injection.
This vulnerability is listed as CVE-2026-54310. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.