High severity7.5NVD Advisory· Published Dec 11, 2019· Updated Jun 17, 2026
CVE-2019-19729
CVE-2019-19729
Description
An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects _bsontype==ObjectID in the user-input object. As a result, objects in arbitrary forms can bypass formatting if they have a valid bsontype.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bson-objectidnpm | <= 1.3.0 | — |
Affected products
2- BSON ObjectID/bson-objectiddescription
Patches
Vulnerability mechanics
References
4- github.com/williamkapke/bson-objectid/issues/30nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-p84x-5xx8-hff9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-19729ghsaADVISORY
- www.npmjs.com/package/bson-objectidnvdProductWEB
News mentions
0No linked articles in our index yet.