VYPR

MongoDB Extension for VS Code

by MongoDB

CVEs (2)

  • CVE-2021-32039MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.00

    Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension…

  • CVE-2026-84967MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades…