๐Ÿ” CVE Alert

CVE-2026-54687

UNKNOWN 0.0

n8n-nodes-sqlite3: Path traversal via user-controlled database file path (db_path parameter)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a remote attacker to select which SQLite file the n8n process opens, enabling traversal outside the intended database location and potentially reading, creating, or overwriting files accessible to the process. This issue is fixed in version 1.0.0.

CWE CWE-22
Vendor dangerblack
Product n8n-node-sqlite3
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for dangerblack n8n-node-sqlite3

Be the first to know when new unknown vulnerabilities affecting dangerblack n8n-node-sqlite3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

DangerBlack / n8n-node-sqlite3
< 1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/DangerBlack/n8n-node-sqlite3/security/advisories/GHSA-q7m3-rhxg-7vxr github.com: https://github.com/DangerBlack/n8n-node-sqlite3/pull/25 github.com: https://github.com/DangerBlack/n8n-node-sqlite3/commit/145a8876ff12375813bdcd4ae4fe78f460c53a98