Tools AI Risk Radar ai-incident-0121
Incident record
n8n patches 16 flaws that expose stored data and credentials
- Severity
- Critical
- Status
- Patched
- Type
- Infra Vuln
- Target
- n8n before 1.123.80, 2.39.6 and 2.40.1, including its AI agent and MongoDB Chat Memory nodes
- Actor
- researcher
- CVE
- CVE-2026-103248, CVE-2026-103255, CVE-2026-103246, CVE-2026-103250
What happened
n8n published 16 CVE records on 1 October 2026, all fixed in 1.123.80, 2.39.6 and 2.40.1. The two highest, both CVSS 3.1 9.0, are in the Supabase node: unescaped filter values let untrusted input read every row, update every record or delete whole tables in one request (CVE-2026-103248), and an unchecked tableId lets a workflow reach Supabase's Auth and Storage APIs with the administrative serviceRole key, bypassing row-level security (CVE-2026-103255).
Two records touch n8n's AI features directly. CVE-2026-103246 (7.7): inline agent node-tool introspection decrypts a credential by its ID without checking who owns it, so an attacker can send the plaintext secret to a host they control. CVE-2026-103250 (8.1): a NoSQL injection in the sessionId of the MongoDB Chat Memory node lets an unauthenticated attacker read other users' conversation histories and write or delete them. The batch follows n8n's 17 CVE records of 8 September on row ai-incident-0085.
Sources
- NVD record CVE-2026-103248nvd.nist.gov/vuln/detail/CVE-2026-103248
- NVD record CVE-2026-103255nvd.nist.gov/vuln/detail/CVE-2026-103255
- NVD record CVE-2026-103246nvd.nist.gov/vuln/detail/CVE-2026-103246
- NVD record CVE-2026-103250nvd.nist.gov/vuln/detail/CVE-2026-103250
- n8n advisory GHSA-xrqg-3xcp-h45xgithub.com/n8n-io/n8n/security/advisories/GHSA-xrqg-3xcp-h45…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 2 October 2026