mediumVulnerability

GHSA-652q-gvq3-74qv

## Impact The n8n Snowflake node's Execute Query operation interpolated expression values directly into the SQL string, making queries built with untrusted data susceptible to SQL injection. Exploitation requires that a workflow author has already embedded untrusted expression data directly in a raw SQL query. ## Patches The issue has been fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Users should upgrade to one of these versions or later to remediate the vulnerability. The fix introduces an optional "Query Parameters" field that allows values to be bound via positional placeholders rather than interpolated into the query string. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict workflow creation and editing permissions to fully trusted users only. - Audit existing workflows that use the Snowflake `executeQuery` operation and ensure no expression resolving to externally-controlled data is embedded directly in a raw SQL query string. - Restrict network access to any webhook or trigger endpoints that feed data into Snowflake `executeQuery` nodes. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Properties

ghsa_id
GHSA-652q-gvq3-74qv
severity
medium
summary
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
cve_id
GHSA-652q-gvq3-74qv
is_ghsa_only
true
ghsa_published
2026-07-22T23:20:24Z
source_url
https://github.com/advisories/GHSA-652q-gvq3-74qv
ghsa_updated
2026-07-22T23:20:25Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-652q-gvq3-74qv — Ninja Signal Threat Intelligence | Ninja Signal