Mongoose MongoDB ODM
87%
Total Score
61
100
100
75
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-42334 mongoose is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 6.13.9, 7.0.0 - 7.8.8, 8.0.0 - 8.22.0 and 9.0.0 - 9.1.5. | 0.0.0 - 6.13.97.0.0 - 7.8.88.0.0 - 8.22.0 +1 more | High |
CVE-2025-23061 mongoose is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 8.0.0-rc0 - 8.9.5, 7.0.0-rc0 - 7.8.4 and 0.0.0 - 6.13.6. | 0.0.0 - 6.13.67.0.0-rc0 - 7.8.48.0.0-rc0 - 8.9.5 | Critical |
AIKIDO-2024-10481 mongoose is vulnerable to NoSQL Injection in versions 5.6.4 - 8.8.2. | 5.6.4 - 8.8.2 | Critical |
CVE-2023-3696 mongoose is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 7.0.0 - 7.3.3, 6.0.0 - 6.11.3 and 0.0.0 - 5.13.20. | 0.0.0 - 5.13.206.0.0 - 6.11.37.0.0 - 7.3.3 | Critical |
CVE-2022-24304 mongoose is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 6.0.0 - 6.4.6 and 0.0.0 - 5.13.15. | 0.0.0 - 5.13.156.0.0 - 6.4.6 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
ms Version 2.1.3 | — | — |
sift Version 17.1.3 | — | — |
mpath Version 0.9.0 | — | — |
kareem Version 3.3.0 | — | — |
mquery Version 6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant