Improper Neutralization of Special Elements in Data Query Logic Affecting n8n-oci-entrypoint package, versions <2.33.4-r0


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.28% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-N8NOCIENTRYPOINT-19502288
  • published3 Sept 2026
  • disclosed20 Aug 2026

Introduced: 20 Aug 2026

NewCVE-2026-77070  (opens in a new tab)
CWE-943  (opens in a new tab)

How to fix?

Upgrade Minimos:latest n8n-oci-entrypoint to version 2.33.4-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream n8n-oci-entrypoint package and not the n8n-oci-entrypoint package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence the resolved query (e.g., via externally-controlled data) can inject operators such as $ne or $where, turning an intended single-document lookup into full-collection disclosure, full-collection deletion, or other operations on the database server.

CVSS Base Scores

version 3.1