I'm pretty sure couchdb has a query language which can receive injections. If you pass JavaScript into mongodb theoretically you could open an injection problem if you don't use parametrization. But unless your nosql database has a native API, it still probably is vulnerable to command injection in the same way SQL databases are. Nothing really special about nosql itself that prevents this.