9.8

CVE-2025-23061

Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoosejsMongoose SwPlatformnode.js Version < 6.13.6
MongoosejsMongoose SwPlatformnode.js Version >= 7.0.0 < 7.8.4
MongoosejsMongoose SwPlatformnode.js Version >= 8.0.0 < 8.9.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.03% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cve@mitre.org 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md
Release Notes
https://www.npmjs.com/package/mongoose?activeTab=versions
Product
https://github.com/Automattic/mongoose/commit/64a9f9706f2428c49e0cfb8e223065acc645f7bc
Patch
https://github.com/Automattic/mongoose/releases/tag/8.9.5
Release Notes