n8n-nodes-sqlite3 File Path Traversal Vulnerability (CVE-2026-54687) — Critical Severity

A critical security flaw has been identified in n8n-nodes-sqlite3, a component used within n8n workflows for interacting with local SQLite databases. This vulnerability, tracked as CVE-2026-54687, could allow malicious actors to gain unauthorized access and potentially manipulate sensitive files on systems running affected versions.

In simple terms, n8n-nodes-sqlite3 works by letting you specify the path to a SQLite database file. The problem was that the software didn’t properly check the information provided for this file path. If someone created a workflow that accepted untrusted input for the database file’s location, an attacker could trick the system. Instead of opening the intended database, the attacker could force n8n to open, read, create, or even overwrite other files on the server where n8n is running. This essentially lets them access areas they shouldn’t, leading to serious security breaches.

CVE Details

  • Product: n8n-nodes-sqlite3
  • CVE ID: CVE-2026-54687
  • Published: August 27, 2026
  • Severity: CRITICAL
  • Status: Analyzed

Affected Products

The vulnerability impacts versions of n8n-nodes-sqlite3 prior to 1.0.0.

Current Status

The vulnerability has been thoroughly analyzed, and a fix is readily available. Developers and system administrators are strongly advised to take immediate action to secure their n8n installations.

Severity Level

This vulnerability is rated as CRITICAL with a CVSS score of 9.8. This high rating reflects the severe potential impact and the ease of exploitation. An attacker exploiting this flaw could achieve significant control over the underlying system, leading to:

  • Confidentiality Breaches: Unauthorized reading of sensitive data from any file accessible to the n8n process.
  • Integrity Compromise: Unauthorized creation or modification of files, potentially leading to system damage or planting malicious code.
  • Availability Impact: Disruption of services by corrupting critical system files.

The fact that a remote attacker can leverage untrusted input to achieve this makes it an extremely dangerous flaw that requires immediate attention.

Possible Solutions

The most effective solution to mitigate CVE-2026-54687 is to update n8n-nodes-sqlite3 to version 1.0.0 or later immediately.

The fix specifically involves setting `noDataExpression: true` on the `db_path` parameter within the node’s configuration. This change prevents untrusted data expressions from upstream workflow inputs (like webhook request bodies) from controlling which SQLite file the n8n process opens, thereby preventing directory traversal attacks.

Beyond applying the patch, it’s always a good practice to:

  • Validate All Inputs: Ensure all data received from external or untrusted sources is rigorously validated and sanitized before being used in file paths or other sensitive operations.
  • Least Privilege: Run n8n processes with the minimum necessary permissions to limit the potential damage if a vulnerability is exploited.

References

https://github.com/DangerBlack/n8n-node-sqlite3/commit/145a8876ff12375813bdcd4ae4fe78f460c53a98

https://github.com/DangerBlack/n8n-node-sqlite3/pull/25

https://github.com/DangerBlack/n8n-node-sqlite3/security/advisories/GHSA-q7m3-rhxg-7vxr

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.