CVE-2026-54310: n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
An authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node’s allowing arbitrary SQL to be injected and executed against the connected database within the privileges of the configured database account.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54310 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →