CVE-2026-33660
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
Summary
Remediation
Upgrade to the fixed version using your package manager.
npm install n8n@2.14.1
npm install n8n@2.13.3
npm install n8n@1.123.27
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (3)
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.9 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References
Frequently Asked Questions
- What is CVE-2026-33660?
- n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.9/10).
- How do I check if my project is affected by CVE-2026-33660?
- CVE-2026-33660 affects n8n. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-33660 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-44789CRITICAL
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
- CVE-2026-25052CRITICAL
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
- CVE-2026-27498CRITICAL
n8n has Arbitrary Command Execution via File Write and Git Operations
- CVE-2026-72763HIGH
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
- CVE-2026-65598HIGH
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
- CVE-2026-65015HIGH
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
- CVE-2025-62726HIGH
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
- CVE-2026-65590MEDIUM
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies