Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform unauthorized write and delete operations.
Published: 2026-10-01
Score: 7 High
EPSS: n/a
KEV: No
Impact: Unauthorized Database Access
Action: Apply Patch
AI Analysis

Impact

This vulnerability is a NoSQL injection flaw in the MongoDB Chat Memory node of n8n. The sessionId parameter is not validated, enabling an attacker to inject MongoDB query operators. By doing so, an unauthenticated user can read conversation histories belonging to other users and perform write and delete operations on those records. The weakness is classified as CWE‑943.

Affected Systems

Affected products are n8n (n8n-io:n8n). Versions prior to 1.123.80, prior to 2.39.6, and prior to 2.40.1 are vulnerable. Upgrades to any newer release of these product lines eliminate the flaw.

Risk and Exploitability

The CVSS score of 7 indicates moderate severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is via unauthenticated access to the Chat Memory node, sending HTTP requests that contain crafted sessionId values. The absence of authentication requirements means that any external actor with network access to the n8n instance could exploit this flaw.

Generated by OpenCVE AI on October 1, 2026 at 14:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.80 or later, 2.39.6 or later, or 2.40.1 or later to remove the vulnerable node implementation.
  • If an immediate upgrade is not possible, mitigate by restricting network access to the n8n instance so only trusted administrators can reach the Chat Memory API endpoint.
  • Consider disabling or removing the MongoDB Chat Memory node configuration until a patch is applied, preventing potential unauthorized data operations.

Generated by OpenCVE AI on October 1, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform unauthorized write and delete operations.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory
First Time appeared N8n
N8n n8n
Weaknesses CWE-943
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:41:56.479Z

Reserved: 2026-09-30T10:52:32.249Z

Link: CVE-2026-103250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:18.777

Modified: 2026-10-01T11:17:18.920

Link: CVE-2026-103250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic