VYPR

mongoose

by Automattic

CVEs (1)

  • CVE-2026-73562MedAug 13, 2026
    risk 0.35cvss 6.5epss

    Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted…