CRITICAL 9.0 npm
Mongoose search injection vulnerability
GHSA-vg7j-7cwx-8wgw · BIT-mongoose-2025-23061 · CVE-2025-23061
Published · Modified
Description
Mongoose versions prior to 8.9.5, 7.8.4, and 6.13.6 are vulnerable to improper use of the $where operator. This vulnerability arises from the ability of the $where clause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.
NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-23061
- WEB https://github.com/Automattic/mongoose/commit/64a9f9706f2428c49e0cfb8e223065acc645f7bc
- PACKAGE https://github.com/Automattic/mongoose
- WEB https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md
- WEB https://github.com/Automattic/mongoose/compare/6.13.5...6.13.6
- WEB https://github.com/Automattic/mongoose/compare/7.8.3...7.8.4
- WEB https://github.com/Automattic/mongoose/compare/8.9.4...8.9.5
- WEB https://github.com/Automattic/mongoose/releases/tag/6.13.6
- WEB https://github.com/Automattic/mongoose/releases/tag/7.8.4
- WEB https://github.com/Automattic/mongoose/releases/tag/8.9.5
- ADVISORY https://github.com/advisories/GHSA-m7xq-9374-9rvx
- WEB https://www.npmjs.com/package/mongoose?activeTab=versions
Ready to move
Start Securing
Free, no credit card | First findings in minutes