Impact
The vulnerability resides in the Mongoid library, which does not neutralize string‑typed query criteria. When an unauthenticated attacker supplies such a criterion, it is forwarded directly to MongoDB as a server‑side JavaScript expression. The database engine evaluates the injected code, enabling the attacker to execute arbitrary code on the database. This can lead to disclosure of sensitive field values, covert selection of documents that the application may subsequently modify, and a measurable degradation of database performance. The flaw is a classic code‑injection weakness (CWE‑94).
Affected Systems
Any deployment that uses MongoDB Inc.’s Mongoid as the ODM is potentially impacted. The advisory does not list specific version ranges, so any installation of Mongoid that permits string query criteria is at risk until a patched version is applied.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability. The EPSS score of less than 1% indicates that current exploitation attempts are unlikely to be widespread, though the vulnerability remains exploitable. It is not recorded in the CISA KEV catalog. The attack can be performed remotely by inserting malicious strings into application inputs that are passed as query criteria, and no authentication is required to trigger the code evaluation.
OpenCVE Enrichment