VDB
Sign up
CRITICAL9.0

GHSA-vg7j-7cwx-8wgw

Mongoose search injection vulnerability

Quick fix

GHSA-vg7j-7cwx-8wgw — mongoose: upgrade to the fixed version with the command below.

npm install mongoose@8.9.5

Details

Mongoose versions prior to 8.9.5, 7.8.4, and 6.13.6 are vulnerable to improper use of the `$where` operator. This vulnerability arises from the ability of the `$where` clause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.

NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongoose
Introduced in: 8.0.0-rc0Fixed in: 8.9.5
Fixnpm install mongoose@8.9.5
npm/mongoose
Introduced in: 7.0.0-rc0Fixed in: 7.8.4
Fixnpm install mongoose@7.8.4
npm/mongoose
Introduced in: 0Fixed in: 6.13.6
Fixnpm install mongoose@6.13.6

References