High severity7.5NVD Advisory· Published Feb 27, 2025· Updated Jun 17, 2026
CVE-2025-1755
CVE-2025-1755
Description
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- MongoDB Inc/MongoDB Compassv5cpe:2.3:a:mongodb:compass:1.0:*:*:*:*:*:*:*Range: 0
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/errata/RHSA-2025:1755.htmlnvdThird Party Advisory
- jira.mongodb.org/browse/COMPASS-9058nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.