Impact
This vulnerability is a NoSQL injection flaw in the MongoDB Chat Memory node of n8n. The sessionId parameter is not validated, enabling an attacker to inject MongoDB query operators. By doing so, an unauthenticated user can read conversation histories belonging to other users and perform write and delete operations on those records. The weakness is classified as CWE‑943.
Affected Systems
Affected products are n8n (n8n-io:n8n). Versions prior to 1.123.80, prior to 2.39.6, and prior to 2.40.1 are vulnerable. Upgrades to any newer release of these product lines eliminate the flaw.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is via unauthenticated access to the Chat Memory node, sending HTTP requests that contain crafted sessionId values. The absence of authentication requirements means that any external actor with network access to the n8n instance could exploit this flaw.
OpenCVE Enrichment