MongoDB Compass
cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*
A prototype pollution vulnerability has been identified in MongoDB Compass within the CSV parsing logic during import. This issue can allow untrusted file paths, but not arguments, to be passed into the 'shell.openExternal' function. Following certain user actions, this could lead to '1-click' command execution.
Exploitation of this vulnerability could result in prototype pollution, allowing an attacker to manipulate the application's object structure. This could potentially be used to execute arbitrary commands through the 'shell.openExternal' function, according to the context of the vulnerability.
Users can update to MongoDB Compass version 1.49.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.