Loading HuntDB...

GHSA-jxr4-4prv-mh83

GitHub Security Advisory

ejson shell parser in MongoDB Compass maybe bypassed

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2.

Affected Packages

npm @mongodb-js/connection-form
Affected versions: 0 (fixed in 1.20.1)

Related CVEs

Key Information

GHSA ID
GHSA-jxr4-4prv-mh83
Published
July 1, 2024 3:32 PM
Last Modified
February 27, 2025 8:59 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
@mongodb-js/connection-form
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.