VYPR
High severity7.5NVD Advisory· Published Feb 27, 2025· Updated Jun 17, 2026

CVE-2025-1756

CVE-2025-1756

Description

mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mongoshnpm
< 2.3.02.3.0

Affected products

15

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.