THREAT OPS › Threat News › [GHSA] GHSA-q7m3-rhxg-7vxr (medium) — n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
[GHSA] GHSA-q7m3-rhxg-7vxr (medium) — n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
GHSA-q7m3-rhxg-7vxr Severity: medium CVE: CVE-2026-54687
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
## Affected versions < 1.0.0
## Patched version 1.0.0
## Description In versions prior to 1.0.0, the SQLite node accepted the database file path as a direct node parameter visible and editable in the workflow. A workflow author who m
Indicators of compromise
- CVE-2026-54687cve
Original source: https://github.com/advisories/GHSA-q7m3-rhxg-7vxr