MEDIUM6.5npm
GHSA-664h-wqgq-64gw· BIT-mongoose-2026-73562, CVE-2026-73562Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Modified: 8/19/2026
package
pkg:npm/mongoose
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Modified: 8/19/2026
Improper Input Validation in Automattic Mongoose
Modified: 11/29/2023
Mongoose Prototype Pollution vulnerability
Modified: 12/6/2023
automattic/mongoose vulnerable to Prototype pollution via Schema.path
Modified: 12/6/2023
Mongoose Vulnerable to Prototype Pollution in Schema Object
Modified: 4/22/2024
Mongoose search injection vulnerability
Modified: 2/5/2026
Remote Memory Exposure in mongoose
Modified: 12/7/2023
Mongoose search injection vulnerability
Modified: 10/3/2025
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
Modified: 5/18/2026