SQL injection in n8n - CVE-2026-54313
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to overwrite documents with attacker-controlled content.
The vulnerability exists due to improper neutralization of special elements in the MongoDB node Find And Replace operation when processing a user-supplied query filter. A remote user can supply a malicious filter value to overwrite documents with attacker-controlled content.
Exploitation requires workflow edit access.