CRITICAL
GHSA-97mg-3cr6-3x4c
Remote Code Execution in mongodb-query-parser
Quick fix
GHSA-97mg-3cr6-3x4c — mongodb-query-parser: upgrade to the fixed version with the command below.
npm install mongodb-query-parser@2.0.0Details
Versions of `mongodb-query-parser` prior to 2.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize queries, allowing attackers to execute arbitrary code in the system. Parsing the following payload executes `touch test-file`:
```'(function () { return (clearImmediate.constructor("return process;")()).mainModule.require("child_process").execSync("touch test-file").toString()})()'```
## Recommendation
Upgrade to version 2.0.0 or later.
Are you affected?
Enter the version of the package you're using.