Executive brief
MongoDB Shell (mongosh) is a command-line tool used by database administrators and developers to interact with MongoDB databases. An attacker who controls a MongoDB cluster can inject hidden malicious commands that execute when a user presses tab to autocomplete text, bypassing normal visibility and obfuscating the attack. The vulnerability requires the user to be connected to the attacker's cluster and interact with the autocomplete feature, but successful exploitation could allow unauthorized access to data or system compromise.
Technical details
The vulnerability is an improper neutralization of special elements in output (CWE-74) within mongosh's autocomplete mechanism. When autocompleting text, the shell fails to properly sanitize control characters that could be used to inject and obfuscate malicious commands. An attacker with partial or full control of a MongoDB cluster can craft malicious autocompletion entries that appear benign but contain hidden control characters and payload instructions. The attack vector is network-based and requires the user to: (1) connect to an attacker-controlled MongoDB cluster, (2) type a prefix that matches the attacker's prepared autocompletion, and (3) press tab to trigger autocompletion. The attacker must have administrative privileges (PR:H) and user interaction is required (UI:R). The impact is high, affecting confidentiality, integrity, and availability across trust boundaries (S:C). The fix is available in mongosh version 2.3.9 and later.
Affected products
- MongoDB mongosh prior to 2.3.9
Timeline
- 2025-02-27: disclosed
- 2025-02-27: patched: Fixed in version 2.3.9