GHSA-4jwp-vfvf-657p
GitHub Security Advisory
Deserialization of Untrusted Data in bson
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.
Affected Packages
npm
bson
Affected versions:
0
(fixed in 1.1.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 7, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.