Junglewise Threat Intelligence

CVE-2025-23061: Mongoose search injection vulnerability via $where operator

CVE-2025-23061 · Severity: low · CVSS 3.1 · Published 2025-01-15

Vendors: Automattic.

Executive brief

Mongoose is a popular JavaScript library for interacting with MongoDB databases. This vulnerability allows attackers to inject and execute arbitrary JavaScript code through improper handling of the $where operator in database queries, potentially enabling unauthorized access to or modification of database records. The flaw is particularly dangerous in applications that accept user input in search or filter operations.

Technical details

The vulnerability stems from incomplete input validation of the $where operator in Mongoose query construction, specifically in the populate() match functionality. The $where clause in MongoDB allows arbitrary JavaScript execution, and Mongoose failed to properly sanitize nested $where expressions. An attacker can craft a malicious query with nested $where operators to execute arbitrary JavaScript code within MongoDB's JavaScript context, potentially achieving code injection and unauthorized data access or manipulation. Patches are available in versions 6.13.6, 7.8.4, and 8.9.5, which disallow nested $where operators in populate match filters.

Affected products

  • Automattic Mongoose Prior to 6.13.6, 7.8.4, and 8.9.5

Timeline

  • 2025-01-15: disclosed: Vulnerability disclosed
  • 2025-01-15: patched: Patches released in versions 6.13.6, 7.8.4, and 8.9.5

References