Intel

AIKIDO-2026-715664

mongodb/mongodb-extension is vulnerable to PHP Object Injection

PHP Object InjectionCVE-2026-96745 Published 2 days ago

63

Medium Risk

This Affects:

PHPmongodb/mongodb-extension
0.0.1 - 1.21.9
Fixed in 1.21.10
2.0.0 - 2.1.9
Fixed in 2.1.10
2.2.0 - 2.5.2
Fixed in 2.5.3
Are you affected? Scan for Free

TL;DR

MongoDB's PHP driver decodes command monitoring events (CommandStartedEvent, CommandSucceededEvent, CommandFailedEvent, ServerHeartbeatSucceededEvent), write result, session, and error reply payloads with a typemap that uses an embedded __pclass field, so it autoloads and instantiates an application class named in that field without calling its constructor. An application with a registered command monitoring subscriber that includes untrusted input in a database operation, or a compromised server response, causes the resulting object's bsonUnserialize() method to run with untrusted data before the operation reaches the server. Impact depends on which Persistable classes the application can autoload, up to remote code execution through gadget classes. The fix adds a skip_odm state that blocks __pclass inference on these paths while keeping it for explicit debug conversions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range, and you register a command monitoring subscriber for database operations that include externally influenced data.

Background info

mongodb/mongodb-extension is vulnerable to PHP Object Injection in versions 0.0.1 - 1.21.9, 2.0.0 - 2.1.9 and 2.2.0 - 2.5.2.

How to fix this

Upgrade the mongodb/mongodb-extension and/or the mongodb library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform