Mongodb
Mongodb Compass: vulnerabilidades y CVE
Mongodb Compass tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96750 | Alta (7.3) | 0.19% | — | 24 sept 2026 | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on… |
| CVE-2026-14881 | Alta (8.4) | 0.21% | — | 22 jul 2026 | When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for… |
| CVE-2026-9101 | Media (5.3) | 0.45% | — | 20 may 2026 | Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution. |
| CVE-2025-1755 | Alta (7.8) | 0.15% | — | 27 feb 2025 | MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in… |
| CVE-2024-6376 | Crítica (9.8) | 0.48% | — | 1 jul 2024 | MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions… |
| CVE-2024-3371 | Media (6.8) | 0.23% | — | 24 abr 2024 | MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users.… |
| CVE-2021-20334 | Alta (7.8) | 0.20% | — | 6 abr 2021 | A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects:… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.