MEDIUM
DangerBlack
CVE published 2026-08-27
CVE-2026-54687
A vulnerability in n8n-nodes-sqlite3 allows remote attackers to potentially read, create, or overwrite files accessible to the process by manipulating the db_path parameter. This issue is fixed in version 1.0.0. The vulnerability arises from the exposure of the db_path database file path as a node parameter, allowing data expressions from upstream workflow input. A workflow author who maps untrusted input [truncated]