Junglewise Threat Intelligence

CVE-2026-29793: Feathers NoSQL injection via WebSocket id parameter in MongoDB adapter

CVE-2026-29793 · Severity: medium · CVSS 4 · Published 2026-03-10

Vendors: npm.

Executive brief

Feathers is a popular Node.js framework for building real-time APIs and applications. The MongoDB adapter contains a NoSQL injection vulnerability that allows remote attackers to send malicious database query operators through WebSocket connections, bypassing service method validation. An attacker can exploit this to retrieve, modify, or delete arbitrary data from MongoDB collections without proper authorization.

Technical details

The vulnerability is a NoSQL injection (CWE-943) in the MongoDB adapter's handling of the id parameter across service methods (get, patch, update, remove). Socket.IO clients can send arbitrary JavaScript objects as the id argument without type validation at the transport layer. These objects pass through the getObjectId() function and are directly embedded into MongoDB queries as operators. An attacker can send payloads like {$ne: null} to match entire collections or use other MongoDB operators to manipulate query logic. The vulnerability requires network access to the Socket.IO endpoint but no authentication. It is fixed in version 5.0.42; versions 5.0.0 through 5.0.41 are affected.

Affected products

  • FeathersJS @feathersjs/mongodb 5.0.0 to 5.0.41

Timeline

  • 2026-03-10: disclosed: Security advisory published
  • 2026-03-10: patched: Fix released in version 5.0.42

References