CVE-2025-23061 is a critical search injection vulnerability affecting Mongoose versions prior to 8.9.5, stemming from an incomplete fix for a previous CVE. This flaw allows attackers to improperly use nested $where filters with populate() matches, potentially leading to remote code execution. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, it presents a significant risk due to its network-based attack vector, low complexity, and severe impact on confidentiality, integrity, and availability. While not yet on the KEV catalog, Nuclei templates exist for detecting this NoSQL injection, and it has garnered substantial community discussion and media coverage, suggesting active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.13.6CPE matchmatch criteria | cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* | ||
>= 7.0.0, < 7.8.4CPE matchmatch criteria | cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* | ||
>= 8.0.0, < 8.9.5CPE matchmatch criteria | cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* | ||
>= 6.0.0, < 6.13.6CPE match | cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.