CRITICAL9.0
GHSA-vg7j-7cwx-8wgw
Mongoose search injection vulnerability
Quick fix
GHSA-vg7j-7cwx-8wgw — mongoose: upgrade to the fixed version with the command below.
npm install mongoose@8.9.5Details
Mongoose versions prior to 8.9.5, 7.8.4, and 6.13.6 are vulnerable to improper use of the `$where` operator. This vulnerability arises from the ability of the `$where` clause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.
NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-23061[ADVISORY]
- https://github.com/Automattic/mongoose/commit/64a9f9706f2428c49e0cfb8e223065acc645f7bc[WEB]
- https://github.com/Automattic/mongoose[PACKAGE]
- https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md[WEB]
- https://github.com/Automattic/mongoose/compare/6.13.5...6.13.6[WEB]
- https://github.com/Automattic/mongoose/compare/7.8.3...7.8.4[WEB]
- https://github.com/Automattic/mongoose/compare/8.9.4...8.9.5[WEB]
- https://github.com/Automattic/mongoose/releases/tag/6.13.6[WEB]
- https://github.com/Automattic/mongoose/releases/tag/7.8.4[WEB]
- https://github.com/Automattic/mongoose/releases/tag/8.9.5[WEB]
- https://github.com/advisories/GHSA-m7xq-9374-9rvx[ADVISORY]
- https://www.npmjs.com/package/mongoose?activeTab=versions[WEB]