Skip to content
High-Risk NoSQL Injection Vulnerability in n8n's MongoDB Chat Memory Node

High-Risk NoSQL Injection Vulnerability in n8n's MongoDB Chat Memory Node

First seen 1 Oct 2026, 21:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 21:05 UTC
  • •CVE-2026-103250 affects n8n versions before 1.123.80 and 2.39.6.
  • •The vulnerability allows unauthenticated access to user conversation histories.
  • •Immediate upgrade or access restrictions are recommended to mitigate risks.

A NoSQL injection vulnerability, CVE-2026-103250, has been identified in n8n versions prior to 1.123.80 and 2.39.6, affecting the MongoDB Chat Memory node. This flaw allows unauthenticated attackers to manipulate the sessionId parameter, potentially accessing and modifying other users' conversation histories. The vulnerability is particularly concerning for self-hosted and internet-accessible deployments using this node without proper authentication. Users are advised to upgrade to the fixed versions or implement temporary mitigations, such as restricting access to trusted users only. The risk is classified as high due to the potential exposure of sensitive information and disruption of workflows. No active exploitation has been confirmed at this time.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-01
CVE-2026-103250 published
A NoSQL injection vulnerability in n8n's MongoDB Chat Memory node was disclosed, affecting multiple versions.
Redpacketsecurity
2026-10-01
GitHub advisory released
GitHub published an advisory detailing the NoSQL injection vulnerability and recommended upgrades.
github.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-103250 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1.
What should I do if I can't upgrade immediately?
Consider restricting access to trusted users only and enabling authentication on Chat Trigger nodes.
Is there any active exploitation reported?
No active exploitation has been confirmed as of now.