Executive brief
The MongoDB integration for Laravel, a popular PHP web framework, contains a flaw in how it validates embedded document identifiers. An authenticated attacker can inject MongoDB query operators into an embedded document key, allowing them to delete all embedded documents in a record or overwrite unintended embedded documents. This could lead to data loss or unauthorized modification of application data.
Technical details
The vulnerability is an improper neutralization of special elements (CWE-89 style operator injection) in the MongoDB query logic. The root cause is that the convertKey() function in src/Query/Builder.php does not validate that id or relation key values are scalars, allowing MongoDB operator documents (arrays with $-prefixed keys like {$ne: null}) to pass through and become live operators in compiled MongoDB filters. Attack vectors include polymorphic relation lookups (MorphTo), embedded document operations (EmbedsMany pull/update), and relation constraints with custom keys. An authenticated user who can influence an embedded record identifier or relation key can exploit this to delete or modify embedded documents. The fix adds operator-document validation in convertKey() and relation constraint paths, rejecting any array containing $-prefixed keys while preserving support for composite _id arrays. Patches are available in version 5.11.0.
Affected products
- MongoDB Laravel Integration before 5.11.0
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in version 5.11.0