NoSQL Injection Vulnerability in n8n MongoDB Node by n8n
CVE-2026-77070

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77070?

The NoSQL injection vulnerability in n8n affects the MongoDB node's Find, Delete, and Aggregate operations, which improperly parse the Query parameter as JSON. This occurs after expression resolution without adequately sanitizing MongoDB operators. An attacker controlling their input can exploit this weakness, allowing them to manipulate queries, leading to unauthorized access or modification of data within the database, including extraction of sensitive information or complete data deletion.

Affected Version(s)

n8n 0 < 1.123.69

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tr4ce-ju
.