VDB
Sign up
HIGH7.0

GHSA-f825-f98c-gj3g

automattic/mongoose vulnerable to Prototype pollution via Schema.path

Quick fix

GHSA-f825-f98c-gj3g — mongoose: upgrade to the fixed version with the command below.

npm install mongoose@6.4.6

Details

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The `Schema.path()` function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongoose
Introduced in: 6.0.0Fixed in: 6.4.6
Fixnpm install mongoose@6.4.6
npm/mongoose
Introduced in: 0Fixed in: 5.13.15
Fixnpm install mongoose@5.13.15

References