CVE-2025-1692

Published Feb 27, 2025

Last updated a month ago

Overview

Description
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted text can be used to obfuscate malicious code. This issue affects mongosh versions prior to 2.3.9
Source
cna@mongodb.com
NVD status
Analyzed
Products
mongosh

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cna@mongodb.com
CWE-150

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.