CVE-2026-54687
n8n-nodes-sqlite3: Path traversal via user-controlled database file path (db_path parameter)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a remote attacker to select which SQLite file the n8n process opens, enabling traversal outside the intended database location and potentially reading, creating, or overwriting files accessible to the process. This issue is fixed in version 1.0.0.
| CWE | CWE-22 |
| Vendor | dangerblack |
| Product | n8n-node-sqlite3 |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for dangerblack n8n-node-sqlite3
Be the first to know when new unknown vulnerabilities affecting dangerblack n8n-node-sqlite3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
DangerBlack / n8n-node-sqlite3
< 1.0.0