MongoDB / Compass
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-96750 | Shell script injection via server-supplied database name in Open MongoDB shell | HIGH | 7.3 | Sep 24, 2026 |
| CVE-2026-9101 | Prototype pollution in csv parsing | MEDIUM | 5.3 | May 20, 2026 |
| CVE-2025-1755 | MongoDB Compass may be susceptible to local privilege escalation in Windows | HIGH | 7.8 | Feb 27, 2025 |
| CVE-2024-6376 | ejson shell parser in MongoDB Compass maybe bypassed | CRITICAL | 9.8 | Jul 1, 2024 |
| CVE-2024-3371 | Insufficient validation of external input in Compass may enable MITM attacks | HIGH | 7.1 | Apr 24, 2024 |
| CVE-2021-20334 | Local privilege escalation in MongoDB Compass for Windows | HIGH | 7.8 | Apr 6, 2021 |
Showing 1 to 4 of 4 CVEs