Critical
Low
Medium

CVE-2024-53900 & CVE-2025-23061 — Mongoose RCE

Overview

Critical
Low
Medium
No items found.

Package: mongoose

Impact: Remote Code Execution via $where operator exploitation

Fix: Update to mongoose v8.9.5+

Year: 2024-2025

CVSS:

Severity:

Affected Components

Location

      * lib/helpers/populate/getModelsMapForPopulate.js

      * getModelsMapForPopulate

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo