There are still some database injections that are possible in MongoDB (although they definitely tend to be less common due to the query language not being text-based). The most common type is when someone directly uses the data from a quest in the query without checking the type; for example, if you have a query that says "delete the user with id ____" and then pass in the id directly from the POST request without checking the type, someone could make a request with a body of `{ "$nin: [] }` (i.e. "not in the empty array"), which would then delete every user in the database. The fix, in this case, is just to check the type of the request data before serializing it into the query; in the example above, you could just return an error if you get anything other than a single user id.