Executive brief
MongoDB Compass, a graphical interface for managing MongoDB databases, is vulnerable to a security flaw when importing CSV files. An attacker could provide a specially crafted CSV file that, when processed by a user, causes the application to open unintended file paths. This could lead to the execution of malicious commands on the user's local system if they interact with the application after the import.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in the CSV parsing logic of MongoDB Compass during the data import process. By crafting a malicious CSV file, an attacker can pollute the object prototype, which subsequently influences the 'shell.openExternal' function in the Electron-based environment. While the vulnerability does not allow for direct argument injection, it enables the injection of untrusted file paths. Successful exploitation requires a user to import the malicious file and perform specific subsequent actions, resulting in a '1-click' command execution scenario. The issue is resolved in MongoDB Compass version 1.49.6.
Affected products
- MongoDB Compass versions prior to 1.49.6
Timeline
- 2026-05-05: other: Issue reported internally/created in Jira
- 2026-05-06: patched: Issue resolved/fixed in development
- 2026-05-20: advisory: CVE published and NVD record created