THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q7m3-rhxg-7vxr (medium) — n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)

[GHSA] GHSA-q7m3-rhxg-7vxr (medium) — n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)

medgithub_advisoriesPublished 2026-08-27

GHSA-q7m3-rhxg-7vxr Severity: medium CVE: CVE-2026-54687

n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)

## Affected versions < 1.0.0

## Patched version 1.0.0

## Description In versions prior to 1.0.0, the SQLite node accepted the database file path as a direct node parameter visible and editable in the workflow. A workflow author who m

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q7m3-rhxg-7vxr