CVE-2026-54313Medium· 7.7▾ Sunlitn8n: NoSQL Injection in MongoDB Node Find And Replace Operation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.3%
An authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being passed to MongoDB as a query filter, allowing unintended documents to be matched and overwritten with attacker-controlled content.
The issue has been fixed in n8n version 2.24.0. Users should upgrade to this version or later to remediate the vulnerability.
If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
n8n-nodes-base.mongoDb to the NODES_EXCLUDE environment variable.These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
n8n < 2.24.0Upgrade to a patched release:
n8n 2.24.0Connected by shared product, vendor, weakness, or advisory.
GHSA-jqwr-vx3p-r266Mediumn8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-652q-gvq3-74qvMediumn8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
CVE-2026-59257Mediumn8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
CVE-2026-54310Medium· 9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform