Mongoose MongoDB ODM
88%
Total Score
60
100
100
80
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-23061 mongoose is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 8.0.0-rc0 - 8.9.5, 7.0.0-rc0 - 7.8.4 and 0.0.0 - 6.13.6. | 0.0.0 - 6.13.67.0.0-rc0 - 7.8.48.0.0-rc0 - 8.9.5 | Critical |
AIKIDO-2024-10481 mongoose is vulnerable to NoSQL Injection in versions 5.6.4 - 8.8.2. | 5.6.4 - 8.8.2 | Critical |
CVE-2023-3696 mongoose is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 7.0.0 - 7.3.3, 6.0.0 - 6.11.3 and 0.0.0 - 5.13.20. | 0.0.0 - 5.13.206.0.0 - 6.11.37.0.0 - 7.3.3 | Critical |
CVE-2022-24304 mongoose is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 6.0.0 - 6.4.6 and 0.0.0 - 5.13.15. | 0.0.0 - 5.13.156.0.0 - 6.4.6 | Critical |
CVE-2022-2564 mongoose is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 6.0.0 - 6.4.6 and 0.0.0 - 5.13.15. | 0.0.0 - 5.13.156.0.0 - 6.4.6 | High |
| Dependency | Last Release | Score |
|---|---|---|
ms Version 2.1.3 | — | — |
sift Version 17.1.3 | — | — |
mpath Version 0.9.0 | — | — |
kareem Version 3.2.0 | — | — |
mquery Version 6.0.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant