Mongoosejs provides an object-data mapper (ODM) for MongoDB in Node.js applications, and despite its narrow product scope, sits in a critical middleware layer across a broad range of web and server-side deployments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrated in its core Mongoose product through prototype-pollution, code-injection, and SQL-injection weaknesses that reflect risks inherent to dynamic property manipulation and query construction in JavaScript-to-database mapping. Defenders should treat Mongoose security advisories as high-priority given the library's depth in the application stack and the severity tendency of its disclosures; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mongoosejs over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2564CRITICAL Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | Jul 28, 2022 | 9.8 | 48 | NO | NO |
CVE-2025-23061CRITICAL Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2 | Jan 15, 2025 | 9.8 | 47 | NO | YES |
CVE-2024-53900CRITICAL Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. | Dec 2, 2024 | 9.1 | 43 | NO | YES |
CVE-2023-3696CRITICAL Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4. | Jul 17, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-42334HIGH Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s s | May 14, 2026 | 7.5 | 28 | NO | NO |
CVE-2019-17426CRITICAL Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, addi | Oct 10, 2019 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mongoosejs.
Media articles that mention a CVE ID that affects a product developed by Mongoosejs — matched by CVE ID, not by vendor name.