PT-2026-85071 · Mongodb · Mongodb Extension For Visual Studio Code+1

CVE-2026-84967

·

Published

2026-09-03

·

Updated

2026-09-10

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MongoDB extension for Visual Studio Code (affected versions not specified)
Description A component of the MongoDB extension for Visual Studio Code fails to neutralize special characters within a connection string before incorporating that value into a command line for an integrated terminal. This allows an unauthenticated remote unauthorized user to inject arbitrary characters into the command line if they can persuade a developer to accept a user-supplied connection target and open the extension's shell feature. The process requires specific user actions, and the confirmation prompt shown to the developer does not display the supplied text.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MONGODB-2026-84967
CVE-2026-84967

Affected Products

Mongodb Extension For Visual Studio Code
Mongodb