What is CVE-2026-72775?
This SQL injection vulnerability exists in the PostgresTrigger node of n8n. User-supplied identifier parameters are interpolated into SQL statements without proper escaping, allowing an authenticated user to inject arbitrary SQL commands.
Azərbaycanca: Bu SQL injection zəifliyi n8n-in PostgresTrigger node-da aşkarlanıb. İstifadəçi tərəfindən təqdim olunan identifikator parametrləri SQL sorğularına düzgün escapə edilmədən daxil edilir ki, bu da autentifikasiya olunmuş şəxsə ixtiyari SQL əmrləri yeritməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which component of n8n was CVE-2026-72775 discovered?
This SQL injection vulnerability was discovered in the PostgresTrigger node of n8n.
Is authentication required to exploit CVE-2026-72775?
Yes, an authenticated user can inject arbitrary SQL commands via the user-supplied identifier parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.