Detects n8n instances where the Data Table Get node's orderByColumn parameter is vulnerable to SQL injection when processed as an expression. The quoteIdentifier() function fails to escape embedded double quotes, allowing identifier breakout. On PostgreSQL deployments, multi-statement execution enables data modification and deletion. Versions <1.123.26, <2.13.3, and 2.14.0 affected.
Is your app exploitable through CVE-2026-33713?
Scan your domain free