Improper Neutralization of Special Elements in Data Query Logic in n8n - #VU150762
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to read, modify, or delete other users\' conversation histories.
The vulnerability exists due to improper neutralization of special elements in a MongoDB query in the MongoDB Chat Memory node when processing sessionId values from Chat Trigger request bodies. A remote attacker can submit a MongoDB query operator in place of a session identifier to read, modify, or delete other users\' conversation histories.
Only workflows that combine an unauthenticated Chat Trigger node with a MongoDB Chat Memory node are affected.