• PATCH AVAILABLE

CVE-2026-77070: nosql injection in n8n-io n8n

Attackers who can shape the query that an n8n MongoDB node executes can inject MongoDB operator payloads to manipulate database operations, potentially exposing or removing many documents; this is tracked as CVE-2026-77070. The vulnerability affects n8n releases before 1.123.69, any 2.0.0–2.33.3 build, and 2.34.0 (fixed in 2.33.4 and 2.34.1). It is triggered when the node accepts a resolved Query parameter and parses it as JSON without filtering dangerous MongoDB operators, and requires an attacker-controlled input path into that query resolution process.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00511
CWE
CWE-943
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a critical injection that can leak or delete large amounts of data; apply the vendor patches now or otherwise isolate MongoDB-related workflows until patched.

What is CVE-2026-77070?

Attackers who can shape the query that an n8n MongoDB node executes can inject MongoDB operator payloads to manipulate database operations, potentially exposing or removing many documents; this is tracked as CVE-2026-77070. The vulnerability affects n8n releases before 1.123.69, any 2.0.0–2.33.3 build, and 2.34.0 (fixed in 2.33.4 and 2.34.1). It is triggered when the node accepts a resolved Query parameter and parses it as JSON without filtering dangerous MongoDB operators, and requires an attacker-controlled input path into that query resolution process.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of n8n-io n8n are affected?

BRANCHAFFECTEDFIXED
1.xbefore 1.123.691.123.69
2.x2.34.0 – before 2.34.12.34.1
2.x2.0.0 – before 2.33.42.33.4

Is CVE-2026-77070 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-77070

  1. Upgrade n8n to 1.123.69 if on the 1.x branch.
  2. Upgrade n8n to 2.33.4 for affected 2.0.0–2.33.x instances or to 2.34.1 for 2.34.0 installations.
  3. Block or restrict network access to n8n and its MongoDB backend to reduce exposure.
  4. Audit workflow inputs and database logs for anomalous queries or unexpected deletion activity.

Frequently asked questions

Is CVE-2026-77070 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which n8n versions are affected by CVE-2026-77070?

Affected releases are versions before 1.123.69, any 2.0.0 through before 2.33.4, and 2.34.0 through before 2.34.1.

Is there a patch for CVE-2026-77070?

Yes. The fixes are included in n8n 1.123.69, 2.33.4, and 2.34.1; upgrade to the matching release for your branch.

What can an attacker do with CVE-2026-77070?

An attacker able to influence the resolved Query value can inject MongoDB operators to retrieve entire collections, delete documents, or run other unintended database commands via the n8n MongoDB node.

References