GHSA-f6mq-5m25-4r72
GitHub Security Advisory
go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers up to (and including) 1.5.0.
Affected Packages
Go
go.mongodb.org/mongo-driver
Affected versions:
0
(fixed in 1.5.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.