MongoDB driver extension
72%
Total Score
caution
Usable with caveats: active MongoDB-backed maintenance is offset by weak GitHub Actions pinning and workflow hygiene.
No repository security policy was found, leaving vulnerability-reporting and response expectations less transparent.
All 42 action references are unpinned, and the audit found high-confidence template-injection and unpinned-image findings plus secrets inheritance; no untrusted checkout or script-injection path was found, so this is a hygiene concern rather than a standalone severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-715664 New mongodb/mongodb-extension is vulnerable to PHP Object Injection in versions 0.0.1 - 1.21.9, 2.0.0 - 2.1.9 and 2.2.0 - 2.5.2. | 0.0.1 - 1.21.92.0.0 - 2.1.92.2.0 - 2.5.2 | Medium |
AIKIDO-2026-561128 New mongodb/mongodb-extension is vulnerable to Out-of-Bounds Read in versions 1.15.0 - 1.21.7, 2.0.0 - 2.1.8 and 2.2.0 - 2.5.0. | 1.15.0 - 1.21.72.0.0 - 2.1.82.2.0 - 2.5.0 | Medium |
AIKIDO-2026-440922 mongodb/mongodb-extension is vulnerable to Improper Neutralization of Special Elements in Data Query Logic in versions 0.0.1 - 1.21.5 and 2.0.0 - 2.4.0. | 0.0.1 - 1.21.52.0.0 - 2.4.0 | High |
CVE-2025-12119 mongodb/mongodb-extension is vulnerable to Expired Pointer Dereference in versions 0.0.0 - 1.21.2. | 0.0.0 - 1.21.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.