mongodb
23 known vulnerabilities · 2 critical · 1 high
MongoDB Driver may publish events containing authentication-related data
Remote code execution via MongoDB BSON parser through prototype pollution
Malicious code in mongodb-atlas-cli-toc-generator (npm)
Malicious code in moonbeam-mongodb (npm)
MongoDB Shell may be susceptible to control character injection via pasting
Malicious code in mongodb-orn (npm)
MongoDB Shell may be susceptible to control character Injection via shell output
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
Malicious code in mongodb-compass (npm)
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
MongoDB Shell may be susceptible to Control Character Injection via autocomplete
Malicious code in mongodb-stitch-browser-testutils (npm)
Malicious code in mongodb-cd (npm)
Malicious code in mongodb-chatbot-verified-answers (npm)
Feathers has a NoSQL Injection via WebSocket id Parameter in MongoDB Adapter
Malicious code in mongodb-stitch-server-testutils (npm)
Malicious code in @voiceflow/nestjs-mongodb (npm)
Malicious code in mongoose-mongodb (npm)
Malicious code in @mastra/mongodb (npm)
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access