PT-2026-50179 · Mongodb+1 · Mongodb+1

·

CVE-2026-54313

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.24.0
Description An authenticated user with workflow edit access can provide a malicious filter value within the MongoDB node's Find And Replace operation. Because the value is not validated before being used as a query filter in MongoDB, it allows unintended documents to be matched and overwritten with content controlled by the attacker.
Recommendations Update to version 2.24.0 or later. Limit workflow creation and editing permissions to fully trusted users only. Disable the MongoDB node by adding n8n-nodes-base.mongoDb to the NODES EXCLUDE environment variable.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54313
GHSA-JPQ7-226W-6CXX

Affected Products

Mongodb
N8N