Automattic Mongoose vulnerabilities
2 known vulnerabilities affecting automattic/mongoose.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-42334P3HIGHCVSS 7.5fixed in 6.13.9v>= 7.0.0, <= 7.8.8+2 more2026-05-14
CVE-2026-42334 [HIGH] CWE-74 CVE-2026-42334: Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to
nvd
CVE-2026-73562P3MEDIUMCVSS 6.5fixed in 6.13.10v>= 7.0.0, < 7.8.10+2 more2026-08-13
CVE-2026-73562 [MEDIUM] CWE-1321 CVE-2026-73562: Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType c
nvd