mongo-express
cpe:2.3:a:mongo-express_project:mongo-express:*:*:*:*:*:*:*
- < 0.54.0
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability exists in mongo-express versions prior to 0.54.0. The issue arises in endpoints that utilize the 'toBSON' method, allowing for the execution of commands through a misuse of the 'vm' dependency in an unsafe environment.
Exploitation of this vulnerability allows for remote code execution on the server where mongo-express is running.
To reproduce this vulnerability, send a request to an endpoint that uses the 'toBSON' method. The 'vm' dependency can then be exploited to execute commands on the server. For example, a command could be crafted to open an application like Calculator on macOS, demonstrating the execution of arbitrary code.
Upgrade mongo-express to version 0.54.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.