Remote Code Execution Vulnerability in NPM mongo-express
Critical severity
GitHub Reviewed
Published
Dec 30, 2019
in
mongo-express/mongo-express
•
Updated Feb 7, 2025
Description
Published by the National Vulnerability Database
Dec 24, 2019
Reviewed
Dec 30, 2019
Published to the GitHub Advisory Database
Dec 30, 2019
Last updated
Feb 7, 2025
Impact
Remote code execution on the host machine by any authenticated user.
Proof Of Concept
Launching mongo-express on a Mac, pasting the following into the "create index" field will pop open the Mac calculator:
Patches
Users should upgrade to version
0.54.0
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
References
Snyk Security Advisory
CVE
For more information
If you have any questions or comments about this advisory:
Thanks
@JLLeitschuh for finding and reporting this vulnerability
References