Impact
Mongoid does not filter query operators that come from externally supplied filter data. When an application forwards such data to Mongoid’s query builder, an unauthenticated party can inject operators that execute JavaScript code within the database. This can expose stored field values to the attacker and degrade database performance by running custom scripts. The weakness is a classic NoSQL injection flaw classified as CWE‑943.
Affected Systems
The vulnerability affects MongoDB Inc.’s Mongoid component. No specific version range is listed in the CNA data; affected builds are those that use the default, unsafe operator guard behavior of Mongoid. Users should verify whether their Mongoid installation is using the default configuration and whether it accepts user supplied query objects for filtering.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% means the likelihood of public exploitation is low at this time. The vulnerability is not yet listed in the CISA KEV catalog. Likely attack vectors are through web or API endpoints that accept query parameters without prior sanitization. An attacker can inject a $where or other JavaScript‑executing operator, leading to data disclosure or a denial‑of‑service by exhausting database resources.
OpenCVE Enrichment