Impact
The MongoDB Rust Driver's GridFS component fails to properly neutralize query‑operator characters in file identifiers. When an authenticated caller supplies a structured identifier that contains operator syntax, the driver interprets it as part of a query instead of a literal value. This flaw allows the attacker to read any file stored in the GridFS bucket or, if they supply a deletion‑style query, to delete all chunks in the bucket, effectively destroying stored data. The weakness is an improper code injection vulnerability (CWE-94) coupled with improper data validation (CWE-943), leading to data disclosure and deletion.
Affected Systems
The vulnerability affects applications that use the MongoDB Rust Driver. No specific driver versions are listed in the current advisory, so the impact extends to all releases until a patched version MongoDB Rust Driver contains an improper neutralization of special elements in its GridFS component (CWE-94, CWE-943). When a caller supplies a structured file identifier that includes query‑operator characters, the driver interprets it as a query condition instead of a literal identifier. This behaviour allows an attacker who can provide or influence the identifier to read file content that exceeds the intended scope or, in a more destructive scenario, to delete every file chunk in the affected GridFS bucket, rendering the stored file content unreadable.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is not disclosed, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user who can influence the file identifier passed by the application. An attacker with such access could potentially retrieve unintended files or permanently delete the bucket contents. The risk is therefore considered moderate to high for systems that expose or do not enforce strict input validation or least‑privilege access.
OpenCVE Enrichment