CVE-2026-59257 — N8n N8n: before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection
n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL string without parameterization. When a workflow uses this operation with expression-sourced values and is connected to an externally-reachable trigger (such as a Webhook node), attacker-controlled input reaching those expressions r CVSSv3.1 8.8 (HIGH)