Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpx3-f8x9-6hqm

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 7.7

Описание

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

EPSS

Процентиль: 27%
0.0034
Низкий

6.3 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 1 месяца назад

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

CVSS3: 7.7
nvd
около 1 месяца назад

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.

CVSS3: 7.7
debian
около 1 месяца назад

A vulnerability was discovered in MongoDB Server where the server-side ...

EPSS

Процентиль: 27%
0.0034
Низкий

6.3 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-862