Description
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
Exploits (3)
github
WORKING POC
6 stars
by AikidoSec · javascriptpoc
https://github.com/AikidoSec/zen-0-days/tree/main/node/CVE-2024-53900
nomisec
WORKING POC
by Gokul-Krishnan-V-R · poc
https://github.com/Gokul-Krishnan-V-R/CVE-2024-53900
Nuclei Templates (1)
Mongoose < 8.8.3 - Remote Code Execution
CRITICALVERIFIEDby h4mg
Shodan:
Server: Mongoose
References (5)
Scores
CVSS v3
9.1
EPSS
0.6415
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Lab Environment
Details
VulnCheck KEV
2025-11-27
CWE
CWE-89
Status
published
Products (4)
mongoosejs/mongoose
7.0.0 rc0
mongoosejs/mongoose
8.0.0 rc0
mongoosejs/mongoose
< 6.13.5
npm/mongoose
8.0.0-rc0 - 8.8.3npm
Published
Dec 02, 2024
Tracked Since
Feb 18, 2026