VDB
Sign up
HIGH7.5

GHSA-f5w3-73h4-jpcm

mongosh vulnerable to local privilege escalation

Quick fix

GHSA-f5w3-73h4-jpcm — mongosh: upgrade to the fixed version with the command below.

npm install mongosh@2.3.0

Details

mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongosh
Introduced in: 0Fixed in: 2.3.0
Fixnpm install mongosh@2.3.0

References