PT-2026-78926 · N8N · N8N

·

CVE-2026-77070

·

Published

2026-08-20

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.69 n8n versions prior to 2.33.4 n8n versions prior to 2.34.1
Description A NoSQL injection issue exists in the MongoDB node's Find, Delete, and Aggregate operations. The software parses the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker capable of influencing the resolved query through externally-controlled data can inject operators like $ne or $where. This can result in full-collection disclosure, full-collection deletion, or other unauthorized operations on the database server.
Recommendations Update to version 1.123.69 or later. Update to version 2.33.4 or later. Update to version 2.34.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77070
GHSA-953P-JM2C-8H5J

Affected Products

N8N