Junglewise Threat Intelligence

CVE-2026-54313: n8n NoSQL injection in MongoDB node Find And Replace operation

CVE-2026-54313 · Severity: high · CVSS 7.7 · Published 2026-06-23

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is an automation platform used to connect different software services and automate business workflows. A security flaw in the MongoDB integration allows users with workflow editing permissions to bypass intended data filters. This could allow an attacker to modify or overwrite sensitive database records that they should not have access to, potentially leading to data corruption or unauthorized information changes.

Technical details

A NoSQL injection vulnerability exists in the n8n MongoDB node's 'Find And Replace' operation. The root cause is a lack of validation for user-supplied filter values before they are passed to the MongoDB query engine. An authenticated attacker with workflow edit permissions can craft a malicious filter to match documents outside the intended scope. Once matched, these documents can be overwritten with attacker-controlled data. The vulnerability is reachable over the network and requires low privileges (workflow edit access). It has been addressed in version 2.24.0; workarounds include disabling the MongoDB node or restricting edit permissions.

Affected products

  • n8n-io n8n < 2.24.0

Timeline

  • 2026-06-10: advisory: GitHub advisory published by vendor
  • 2026-06-23: disclosed: NVD publication date

References

Related threats