Impact
The MongoSQL Transition Readiness Tool writes database and collection names into generated CSV reports without neutralizing leading characters that spreadsheet programs treat as formulas. A user with write permissions on the cluster can choose a namespace name that later evaluates as a formula when an analyst opens the report in a spreadsheet application, potentially revealing report data or executing external content on the analyst’s workstation. This flaw corresponds to CWE‑1236 and can lead to unintended disclosure or code execution on the victim’s machine.
Affected Systems
Affected systems include MongoDB’s BI Connector Transition Readiness Report component. No specific product version range is listed in the CVE data, so all versions of the tool are potentially impacted.
Risk and Exploitability
The CVSS score is 5.8, indicating moderate risk, and there is no EPSS score available. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. Exploitation requires a malicious user to create a namespace with a formula‑starting character and a recipient to open the CSV in a spreadsheet that evaluates formulas, making the risk dependent on user roles and spreadsheet usage.
OpenCVE Enrichment