MongoDB Compass Prototype Pollution Vulnerability in CSV Import Logic

Vulnerability

A prototype pollution vulnerability has been identified in MongoDB Compass within the CSV parsing logic during import. This issue can allow untrusted file paths, but not arguments, to be passed into the 'shell.openExternal' function. Following certain user actions, this could lead to '1-click' command execution.

Impact

Exploitation of this vulnerability could result in prototype pollution, allowing an attacker to manipulate the application's object structure. This could potentially be used to execute arbitrary commands through the 'shell.openExternal' function, according to the context of the vulnerability.

Remediation

Users can update to MongoDB Compass version 1.49.6 to address this vulnerability.

Added: May 20, 2026, 5:31 PM
Updated: May 20, 2026, 5:31 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
4.2
remediation
7.7
relevance
8.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.