VYPR
Critical severity9.0NVD Advisory· Published Jan 15, 2025· Updated Jun 17, 2026

CVE-2025-23061

CVE-2025-23061

Description

Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mongoosenpm
>= 8.0.0-rc0, < 8.9.58.9.5
mongoosenpm
>= 7.0.0-rc0, < 7.8.47.8.4
mongoosenpm
< 6.13.66.13.6

Affected products

4
  • cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:*range: <6.13.6
    • (no CPE)range: 6.0.0
  • osv-coords2 versions
    >= 6.0.0, < 6.13.6+ 1 more
    • (no CPE)range: >= 6.0.0, < 6.13.6
    • (no CPE)range: >= 8.0.0-rc0, < 8.9.5

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.