Impact
The vulnerability in MongoDB Compass allows an attacker to import a connection file that specifies a custom browser open command for the OIDC authentication flow. When the connection is established, this command is executed in the user's shell, giving the attacker arbitrary shell command execution on the machine running Compass. This represents a high‑severity remote code execution flaw, listed with a CVSS score of 8.4.
Affected Systems
MongoDB Compass is affected. No specific version range is listed, but the advisory references the release of v1.49.7, implying that earlier versions – including those prior to this release – are vulnerable.
Risk and Exploitability
With a high CVSS score and an EPSS score of less than 1%, the risk remains significant, particularly in environments where users can import connection files. The vulnerability has not been reported in the CISA KEV catalog. Based on the description, the likely attack vector is that the attacker must provide or gain access to a crafted import file; thus, it is most actionable for local or compromised users. The lack of an exploit reference suggests the vector may not be public yet, but the severity merits prompt action.
OpenCVE Enrichment