Junglewise Threat Intelligence

CVE-2025-1756: MongoDB mongosh local privilege escalation

CVE-2025-1756 · Severity: low · CVSS 3.1 · Published 2025-02-27

Technologies: mongosh (npm). Vendors: npm, MongoDB.

Executive brief

mongosh is a command-line shell for interacting with MongoDB databases. This vulnerability allows a local attacker with user-level access to escalate their privileges to administrator or system level by placing a crafted file in the C:\node_modules directory. A successful exploit could give an attacker control over the entire system when mongosh is run with elevated privileges.

Technical details

This is an untrusted search path vulnerability (CWE-426) in mongosh versions prior to 2.3.0. The vulnerability occurs on Windows systems where mongosh loads modules from C:\node_modules without proper validation of file integrity or origin. An attacker with local file system access can plant a malicious module in this shared directory; when mongosh executes with elevated privileges (e.g., through a scheduled task or sudo on Windows equivalents), the malicious code runs with those elevated privileges. The attack requires user interaction or administrative action to trigger mongosh execution. The fix is available in mongosh 2.3.0 and later.

Affected products

  • MongoDB mongosh prior to 2.3.0

Timeline

  • 2025-02-27: disclosed
  • 2025-02-27: patched: Version 2.3.0 fixes the vulnerability

References

Related threats