CVE-2026-85167CWE-943

CVE-2026-85167

published September 3, 2026

CVSS
6.3
EPSS
0%
Percentile
15.4
In the wild
Unconfirmed
What it is

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly into the query string before parsing. A value containing quote and brace characters can close the intended field and introduce new query operators, turning an intended single-document lookup into a full-collection read.

The record
Technical detail
CVSS
6.3 · NONE
CVSS v4.0
6.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
EPSS
0.00243 · 15.4th percentile
Weakness
CWE-943 · Improper Neutralization of Special Elements in Data Query Logic
Published
2026-09-03T17:06Z
References (2)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 11:22Z
    n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes
    cvelistv5