CVE-2024-53900

CRITICAL EXPLOITED NUCLEI LAB

Mongoose <8.8.3 - SQL Injection

Title source: llm

Description

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

Exploits (3)

github WORKING POC 6 stars
by AikidoSec · javascriptpoc
https://github.com/AikidoSec/zen-0-days/tree/main/node/CVE-2024-53900
nomisec WORKING POC
by www-spam · infoleak
https://github.com/www-spam/CVE-2024-53900
nomisec WORKING POC
by Gokul-Krishnan-V-R · poc
https://github.com/Gokul-Krishnan-V-R/CVE-2024-53900

Nuclei Templates (1)

Mongoose < 8.8.3 - Remote Code Execution
CRITICALVERIFIEDby h4mg
Shodan: Server: Mongoose

Scores

CVSS v3 9.1
EPSS 0.6415
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

VulnCheck KEV 2025-11-27
CWE
CWE-89
Status published
Products (4)
mongoosejs/mongoose 7.0.0 rc0
mongoosejs/mongoose 8.0.0 rc0
mongoosejs/mongoose < 6.13.5
npm/mongoose 8.0.0-rc0 - 8.8.3npm
Published Dec 02, 2024
Tracked Since Feb 18, 2026