DIRAS TAKE
Urgent: this is a critical injection that can leak or delete large amounts of data; apply the vendor patches now or otherwise isolate MongoDB-related workflows until patched.
What is CVE-2026-77070?
Attackers who can shape the query that an n8n MongoDB node executes can inject MongoDB operator payloads to manipulate database operations, potentially exposing or removing many documents; this is tracked as CVE-2026-77070. The vulnerability affects n8n releases before 1.123.69, any 2.0.0–2.33.3 build, and 2.34.0 (fixed in 2.33.4 and 2.34.1). It is triggered when the node accepts a resolved Query parameter and parses it as JSON without filtering dangerous MongoDB operators, and requires an attacker-controlled input path into that query resolution process.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of n8n-io n8n are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | before 1.123.69 | 1.123.69 |
| 2.x | 2.34.0 – before 2.34.1 | 2.34.1 |
| 2.x | 2.0.0 – before 2.33.4 | 2.33.4 |
Is CVE-2026-77070 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-77070
- Upgrade n8n to 1.123.69 if on the 1.x branch.
- Upgrade n8n to 2.33.4 for affected 2.0.0–2.33.x instances or to 2.34.1 for 2.34.0 installations.
- Block or restrict network access to n8n and its MongoDB backend to reduce exposure.
- Audit workflow inputs and database logs for anomalous queries or unexpected deletion activity.
Frequently asked questions
Is CVE-2026-77070 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which n8n versions are affected by CVE-2026-77070?
Affected releases are versions before 1.123.69, any 2.0.0 through before 2.33.4, and 2.34.0 through before 2.34.1.
Is there a patch for CVE-2026-77070?
Yes. The fixes are included in n8n 1.123.69, 2.33.4, and 2.34.1; upgrade to the matching release for your branch.
What can an attacker do with CVE-2026-77070?
An attacker able to influence the resolved Query value can inject MongoDB operators to retrieve entire collections, delete documents, or run other unintended database commands via the n8n MongoDB node.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77070
- cve.org/CVERecord?id=CVE-2026-77070
- github.com/n8n-io/n8n/security/advisories/GHSA-953p-jm2c-8h5j
- vulncheck.com/advisories/n8n-before-nosql-injection-via-mongodb-node
- All n8n-io CVEs on CVE Radar
- CVEs published in September 2026