"NoSQL means Not-injectable, right?" makes no sense for me. It doesnt matter which type of database technology you are using. As any other database there are security roles. No mongodb query should be executed as an admin. You can restrict that up to document level. You can even create read-only views. You should always validate you payload. Use e.g Joi https://github.com/hapijs/joi. Someone who doesn't validate his payload and pass it up to the driver should not be surprised.