Remote Code Execution Vulnerability in NPM mongo-express
Critical severity
GitHub Reviewed
Published
Dec 30, 2019
in
mongo-express/mongo-express
•
Updated Sep 12, 2023
Description
Reviewed
Dec 30, 2019
Published to the GitHub Advisory Database
Dec 30, 2019
Last updated
Sep 12, 2023
Impact
Remote code execution on the host machine by any authenticated user.
Proof Of Concept
Launching mongo-express on a Mac, pasting the following into the "create index" field will pop open the Mac calculator:
Patches
Users should upgrade to version
0.54.0
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
References
Snyk Security Advisory
CVE
For more information
If you have any questions or comments about this advisory:
Thanks
@JLLeitschuh for finding and reporting this vulnerability
References