VYPR

Mongoid

by Mongoid

CVEs (2)

  • CVE-2026-93765CriSep 18, 2026
    risk 0.59cvss 9.1epss

    Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the…

  • CVE-2026-93758HigSep 18, 2026
    risk 0.53cvss 8.1epss

    An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up…