NoSQL Injection Vulnerability in n8n MongoDB Node by n8n
CVE-2026-77070
7.1HIGH
What is CVE-2026-77070?
The NoSQL injection vulnerability in n8n affects the MongoDB node's Find, Delete, and Aggregate operations, which improperly parse the Query parameter as JSON. This occurs after expression resolution without adequately sanitizing MongoDB operators. An attacker controlling their input can exploit this weakness, allowing them to manipulate queries, leading to unauthorized access or modification of data within the database, including extraction of sensitive information or complete data deletion.
Affected Version(s)
n8n 0 < 1.123.69
n8n 2.34.0 < 2.34.1
n8n 2.0.0 < 2.33.4
