mongodb/mongodb-extension is vulnerable to PHP Object Injection
63
Medium Risk
MongoDB's PHP driver decodes command monitoring events (CommandStartedEvent, CommandSucceededEvent, CommandFailedEvent, ServerHeartbeatSucceededEvent), write result, session, and error reply payloads with a typemap that uses an embedded __pclass field, so it autoloads and instantiates an application class named in that field without calling its constructor. An application with a registered command monitoring subscriber that includes untrusted input in a database operation, or a compromised server response, causes the resulting object's bsonUnserialize() method to run with untrusted data before the operation reaches the server. Impact depends on which Persistable classes the application can autoload, up to remote code execution through gadget classes. The fix adds a skip_odm state that blocks __pclass inference on these paths while keeping it for explicit debug conversions.
You are affected if you are using a version that falls within the vulnerable range, and you register a command monitoring subscriber for database operations that include externally influenced data.
mongodb/mongodb-extension is vulnerable to PHP Object Injection in versions 0.0.1 - 1.21.9, 2.0.0 - 2.1.9 and 2.2.0 - 2.5.2.
Upgrade the mongodb/mongodb-extension and/or the mongodb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.