CVE-2024-6376

HIGH

MongoDB Compass <1.42.2 - Code Injection

Title source: llm
STIX 2.1

Description

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory
https://jira.mongodb.org/browse/COMPASS-7496

Scores

CVSS v3 7.0
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-94
Status published
Products (2)
mongodb/compass < 1.42.2
mongodb-js/connection-form 0 - 1.20.1npm
Published Jul 01, 2024
Tracked Since Feb 18, 2026