CVE-2026-103255 is a path traversal flaw in n8n's Supabase node. Workflows that pass untrusted input into the tableId parameter can reach Supabase Auth and Storage APIs with the administrative serviceRole key, which bypasses Row Level Security.
What Is It
n8n's Supabase node puts the tableId parameter into request paths without validating it. If a workflow binds tableId to untrusted input, an attacker can traverse out of the intended table path and reach Supabase's Auth and Storage APIs. Those requests run with the administrative serviceRole key configured in the node, so they skip Row Level Security. Depending on how the workflow and the Supabase project are configured, this can let an attacker read or modify data that those APIs can reach.
The weakness is classified as CWE-73 (External Control of File Name or Path). VulnCheck disclosed the issue, and NVD published it on October 1, 2026. Its NVD status is currently "Deferred."
Why It Matters
VulnCheck scores it 9.0 (CRITICAL) under CVSS 3.1 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). The attack works over the network, needs no privileges or user interaction, and has a changed scope with high confidentiality, integrity and availability impact. Under CVSS 4.0 it scores 7.1 (HIGH). That vector puts the main impact on downstream systems: high confidentiality, integrity and availability impact on the subsequent system.
The main risk is a scope jump. The serviceRole key is an administrative credential, so traversal moves an attacker from a table operation into Auth and Storage functions that Row Level Security would normally protect. Exploitation requires a workflow that binds tableId to untrusted input, which matches the high attack complexity and "attack requirements present" ratings.
As of publication, CVE-2026-103255 is not listed in CISA's Known Exploited Vulnerabilities catalog, and none of the cited sources report exploitation in the wild.
What's Vulnerable
n8n (npm package n8n), in these versions:
- All versions before 1.123.80
- 2.0.0 up to, but not including, 2.39.6
- 2.40.0 up to, but not including, 2.40.1
Only deployments that use the Supabase node with tableId bound to untrusted input are exposed.
Patch Status
The affected ranges end at fixed releases. Upgrade to 1.123.80, 2.39.6 or 2.40.1 or later, depending on your release line. CISA has issued no required action because there is no KEV listing. Review the vendor advisory for any further guidance. Until you upgrade, audit workflows where the Supabase node's tableId comes from external or user-supplied input.