Impact
Mongoid's query path for embedded documents uses unsafe reflection, allowing a crafted externally supplied field name to be executed as code. This flaw permits any unauthenticated user to unintentionally expose stored document data and to permanently delete records, leading to confidentiality and integrity violations.
Affected Systems
MongoDB Inc.'s Mongoid library. No specific version information is provided in the advisory; administrators should verify which releases contain the vulnerability and ensure their installations are updated accordingly.
Risk and Exploitability
The CVSS score of 9.2 reflects a high severity vulnerability, yet the EPSS score is below 1%, indicating that exploitation is currently low probability. The likely attack vector is any interface that forwards user‑provided field names to Mongoid’s in‑memory query methods, with no need for authentication, based on the description. As the vulnerability is not listed in CISA’s KEV catalog, it is not known to be actively exploited in the wild, but the potential impact warrants prompt remediation.
OpenCVE Enrichment