PT-2026-42201 · Mongodb · Compass
CVE-2026-9101
·
Published
2026-05-20
·
Updated
2026-07-23
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
Prototype pollution occurs within the CSV parsing logic during the import process. This issue allows untrusted file paths to be passed to the
shell.openExternal() function. When combined with specific user behavior, this can result in one-click command execution. Prototype pollution is a vulnerability where an attacker manipulates the prototype of a JavaScript object, potentially altering the behavior of other objects in the application.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Compass