PT-2026-42201 · Mongodb · Compass

CVE-2026-9101

·

Published

2026-05-20

·

Updated

2026-07-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Prototype pollution occurs within the CSV parsing logic during the import process. This issue allows untrusted file paths to be passed to the shell.openExternal() function. When combined with specific user behavior, this can result in one-click command execution. Prototype pollution is a vulnerability where an attacker manipulates the prototype of a JavaScript object, potentially altering the behavior of other objects in the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9101

Affected Products

Compass