VDB
Sign up
CRITICAL

GHSA-97mg-3cr6-3x4c

Remote Code Execution in mongodb-query-parser

Quick fix

GHSA-97mg-3cr6-3x4c — mongodb-query-parser: upgrade to the fixed version with the command below.

npm install mongodb-query-parser@2.0.0

Details

Versions of `mongodb-query-parser` prior to 2.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize queries, allowing attackers to execute arbitrary code in the system. Parsing the following payload executes `touch test-file`:

```'(function () { return (clearImmediate.constructor("return process;")()).mainModule.require("child_process").execSync("touch test-file").toString()})()'```

## Recommendation

Upgrade to version 2.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongodb-query-parser
Introduced in: 0Fixed in: 2.0.0
Fixnpm install mongodb-query-parser@2.0.0

References