CVE-2026-29793 is a critical vulnerability affecting Feathersjs versions 5.0.0 through 5.0.41, where Socket.IO clients can inject arbitrary JavaScript objects as the 'id' argument, which are then directly used in MongoDB queries without proper validation. This network-based attack, with low complexity, enables unauthenticated attackers to execute arbitrary database operations, resulting in a critical impact on data confidentiality, integrity, and availability (CVSS 9.8). While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code, or significant community discussion. Organizations using affected Feathersjs versions should upgrade to 5.0.42 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.42CPE matchmatch criteria | cpe:2.3:a:feathersjs:feathers:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.