CRITICAL9.8
GHSA-hxmg-hm46-cf62
Remote code execution in mongo-express
Quick fix
GHSA-hxmg-hm46-cf62 — mongodb-query-parser: upgrade to the fixed version with the command below.
npm install mongodb-query-parser@2.0.0Details
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Are you affected?
Enter the version of the package you're using.