Critical severity9.0NVD Advisory· Published Jan 15, 2025· Updated Jun 17, 2026
CVE-2025-23061
CVE-2025-23061
Description
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mongoosenpm | >= 8.0.0-rc0, < 8.9.5 | 8.9.5 |
mongoosenpm | >= 7.0.0-rc0, < 7.8.4 | 7.8.4 |
mongoosenpm | < 6.13.6 | 6.13.6 |
Affected products
4cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:*range: <6.13.6
- (no CPE)range: 6.0.0
- osv-coords2 versions
>= 6.0.0, < 6.13.6+ 1 more
- (no CPE)range: >= 6.0.0, < 6.13.6
- (no CPE)range: >= 8.0.0-rc0, < 8.9.5
Patches
Vulnerability mechanics
References
12- github.com/Automattic/mongoose/commit/64a9f9706f2428c49e0cfb8e223065acc645f7bcnvdPatchWEB
- github.com/advisories/GHSA-m7xq-9374-9rvxghsaADVISORY
- github.com/advisories/GHSA-vg7j-7cwx-8wgwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-23061ghsaADVISORY
- github.com/Automattic/mongoose/blob/master/CHANGELOG.mdnvdRelease NotesWEB
- github.com/Automattic/mongoose/compare/6.13.5...6.13.6ghsaWEB
- github.com/Automattic/mongoose/compare/7.8.3...7.8.4ghsaWEB
- github.com/Automattic/mongoose/compare/8.9.4...8.9.5ghsaWEB
- github.com/Automattic/mongoose/releases/tag/6.13.6ghsaWEB
- github.com/Automattic/mongoose/releases/tag/7.8.4ghsaWEB
- github.com/Automattic/mongoose/releases/tag/8.9.5nvdRelease NotesWEB
- www.npmjs.com/package/mongoosenvdProductWEB
News mentions
0No linked articles in our index yet.