SQL injection in n8n - CVE-2026-54313
Published: June 16, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite documents with attacker-controlled content.
The vulnerability exists due to improper neutralization of special elements in the MongoDB node Find And Replace operation when processing a user-supplied query filter. A remote user can supply a malicious filter value to overwrite documents with attacker-controlled content.
Exploitation requires workflow edit access.