CVE-2026-54313

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being passed to MongoDB as a query filter, allowing unintended documents to be matched and overwritten with attacker-controlled content. This vulnerability is fixed in 2.24.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

25 Jun 2026, 18:42

Type Values Removed Values Added
First Time N8n
N8n n8n
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-jpq7-226w-6cxx - () https://github.com/n8n-io/n8n/security/advisories/GHSA-jpq7-226w-6cxx - Mitigation, Vendor Advisory
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7

23 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 16:17

Updated : 2026-06-25 18:42


NVD link : CVE-2026-54313

Mitre link : CVE-2026-54313

CVE.ORG link : CVE-2026-54313


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')