VDB
Sign up
HIGH7.5

GHSA-wpg9-53fq-2r8h

Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Quick fix

GHSA-wpg9-53fq-2r8h — mongoose: upgrade to the fixed version with the command below.

npm install mongoose@6.13.9

Details

### Impact

This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the `$nor` operator.

When sanitizeFilter is enabled, Mongoose wraps query operators in `$eq` to neutralize them. However, prior to the fix, `$nor` was not included in the set of logical operators that are recursively sanitized. Because `$nor` accepts an array (like `$and` and `$or`), and arrays do not trigger `hasDollarKeys()`, malicious operators such as `$ne`, `$gt`, or `$regex` could be injected inside a `$nor` clause without being sanitized.

This may lead to:

- Authentication bypass - Unauthorized data access - Data exfiltration

**Affected users:**

Applications that:

- Explicitly enable sanitizeFilter - Pass unsanitized user-controlled input directly into query methods (e.g., `Model.findOne(req.body)`) and rely on `sanitizeFilter` to strip out query selectors

Applications that validate input schemas, whitelist fields, or avoid passing raw request bodies into queries are not affected. For example, `Model.findOne({ user: req.body.user, pwd: req.body.pwd })` is not affected.

### Patches

Patches have been released for all supported Mongoose release lines:

- `^6.13.9` - `^7.8.9` - `^8.22.1` - `^9.1.6`

### Workarounds

Delete `$nor` keys, use an additional schema validation library, or write middleware to strip out `$nor` from query filters.

### Resources

sanitizeFilter documentation: https://mongoosejs.com/docs/api/mongoose.html#Mongoose.prototype.sanitizeFilter()

Original blog post on sanitizeFilter: https://thecodebarbarian.com/whats-new-in-mongoose-6-sanitizefilter.html

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongoose
Introduced in: 0Fixed in: 6.13.9
Fixnpm install mongoose@6.13.9
npm/mongoose
Introduced in: 7.0.0Fixed in: 7.8.9
Fixnpm install mongoose@7.8.9
npm/mongoose
Introduced in: 8.0.0Fixed in: 8.22.1
Fixnpm install mongoose@8.22.1
npm/mongoose
Introduced in: 9.0.0Fixed in: 9.1.6
Fixnpm install mongoose@9.1.6

References