Skip to content

fix(deps): update dependency mongoose to v7.8.10 [security] - #878

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-mongoose-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-mongoose-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Dec 3, 2024 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mongoose (source) 7.6.5 → 7.8.10 age adoption passing confidence

Mongoose search injection vulnerability

CVE-2024-53900 / GHSA-m7xq-9374-9rvx

More information

Details

Mongoose versions prior to 8.8.3, 7.8.3, 6.13.5, and 5.13.23 are vulnerable to improper use of the $where operator. This vulnerability arises from the ability of the $where clause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Mongoose search injection vulnerability

CVE-2025-23061 / GHSA-vg7j-7cwx-8wgw

More information

Details

Mongoose versions prior to 8.9.5, 7.8.4, and 6.13.6 are vulnerable to improper use of the $where operator. This vulnerability arises from the ability of the $where clause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.

NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

Severity

  • CVSS Score: 9.0 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

CVE-2026-42334 / GHSA-wpg9-53fq-2r8h

More information

Details

Impact

This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator.

When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized.

This may lead to:

  • Authentication bypass
  • Unauthorized data access
  • Data exfiltration

Affected users:

Applications that:

  • Explicitly enable sanitizeFilter
  • Pass unsanitized user-controlled input directly into query methods (e.g., Model.findOne(req.body)) and rely on sanitizeFilter to strip out query selectors

Applications that validate input schemas, whitelist fields, or avoid passing raw request bodies into queries are not affected. For example, Model.findOne({ user: req.body.user, pwd: req.body.pwd }) is not affected.

Patches

Patches have been released for all supported Mongoose release lines:

  • ^6.13.9
  • ^7.8.9
  • ^8.22.1
  • ^9.1.6
Workarounds

Delete $nor keys, use an additional schema validation library, or write middleware to strip out $nor from query filters.

Resources

sanitizeFilter documentation: https://mongoosejs.com/docs/api/mongoose.html#Mongoose.prototype.sanitizeFilter()

Original blog post on sanitizeFilter: https://thecodebarbarian.com/whats-new-in-mongoose-6-sanitizefilter.html

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Mongoose: Prototype pollution in mongoose update casting via proto-prefixed dotted path (Schema._getSchema/path getter)

CVE-2026-73562 / GHSA-664h-wqgq-64gw

More information

Details

Impact

What kind of vulnerability is it? Who is impacted?

Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like MyModel.updateOne(filter, req.body), can cause Mongoose to set $fullPath and $parentSchemaDocArray on Object.prototype.

Example:

const mongoose = require('mongoose');
console.log('before:', Object.prototype.$fullPath);            // undefined

const User = mongoose.model('User', new mongoose.Schema({ name: String }));
const malicious = JSON.parse('{"$set": {"__proto__.x": "anything"}}');   // attacker-controlled update

const q = User.updateOne({}, {});
try { q._castUpdate(malicious); } catch (e) { /* throws AFTER the pollution side-effect */ }

console.log('after :', Object.prototype.$fullPath);            // "__proto__"
console.log('enumerable:', Object.prototype.propertyIsEnumerable('$fullPath'));  // true
console.log('fresh {}:', ({}).$fullPath);                      // "__proto__"
Patches

Has the problem been patched? What versions should users upgrade to?

9.7.2, 8.24.1. 7.8.10, 6.13.10

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Check user-controlled updates for own __proto__ properties before passing to Mongoose

References

Are there any links users can visit to find out more?

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

Automattic/mongoose (mongoose)

v7.8.10

Compare Source

7.8.10 / 2026-06-22

  • fix(document): add additional defensive checks for special properties in Document.prototype.get()
  • fix(schema): avoid returning inherited properties from schema path lookups
  • docs(schema): add instanceof/typeof checks to default getter examples for populated docs and nullish values #​16272 #​16250

v7.8.9

Compare Source

==================

  • fix: handle other top-level query operators in sanitizeFilter

v7.8.8

Compare Source

==================

v7.8.7

Compare Source

==================

v7.8.6

Compare Source

===================

  • chore: remove coverage output from bundle

v7.8.5

Compare Source

===================

  • chore: re-release to force npm audit to pick up 6.x fix for CVE-2025-23061

v7.8.4

Compare Source

===================

v7.8.3

Compare Source

==================

  • fix: disallow using $where in match
  • fix(projection): avoid setting projection to unknown exclusive/inclusive if elemMatch on a Date, ObjectId, etc. #​14894 #​14893
  • docs(migrating_to_7): add note about keepAlive to Mongoose 7 migration guide #​15032 #​13431

v7.8.2

Compare Source

==================

  • fix(projection): avoid setting projection to unknown exclusive/inclusive if elemMatch on a Date, ObjectId, etc. #​14894 #​14893

v7.8.1

Compare Source

==================

  • fix(query): handle casting $switch in $expr #​14761
  • docs(mongoose): remove out-of-date callback-based example for mongoose.connect() #​14811 #​14810

v7.8.0

Compare Source

==================

v7.7.0

Compare Source

==================

  • feat(model): add throwOnValidationError option for opting into getting MongooseBulkWriteError if all valid operations succeed in bulkWrite() and insertMany() #​14599 #​14587 #​14572 #​13410

v7.6.13

Compare Source

===================

  • fix(query): shallow clone $or and $and array elements to avoid mutating query filter arguments #​14614 #​14610
  • types: pass DocType down to subdocuments so HydratedSingleSubdocument and HydratedArraySubdocument toObject() returns correct type #​14612 #​14601
  • docs(migrating_to_7): add id setter to Mongoose 7 migration guide #​14645 #​13672

v7.6.12

Compare Source

===================

v7.6.11

Compare Source

===================

  • fix(populate): avoid match function filtering out null values in populate result #​14518
  • fix(schema): support setting discriminator options in Schema.prototype.discriminator() #​14493 #​14448
  • fix(schema): deduplicate idGetter so creating multiple models with same schema doesn't result in multiple id getters #​14492 #​14457

v7.6.10

Compare Source

===================

  • docs(model): add extra note about lean option for insertMany() skipping casting #​14415
  • docs(mongoose): add options.overwriteModel details to mongoose.model() docs #​14422

v7.6.9

Compare Source

==================

  • fix(document): handle embedded recursive discriminators on nested path defined using Schema.prototype.discriminator #​14256 #​14245
  • types(model): correct return type for findByIdAndDelete() #​14233 #​14190
  • docs(connections): add note about using asPromise() with createConnection() for error handling #​14364 #​14266
  • docs(model+query+findoneandupdate): add more details about overwriteDiscriminatorKey option to docs #​14264 #​14246

v7.6.8

Compare Source

==================

  • perf(schema): remove unnecessary lookahead in numeric subpath check
  • fix(discriminator): handle reusing schema with embedded discriminators defined using Schema.prototype.discriminator #​14202 #​14162
  • fix(ChangeStream): avoid suppressing errors in closed change stream #​14206 #​14177

v7.6.7

Compare Source

==================

  • fix: avoid minimizing single nested subdocs if they are required #​14151 #​14058
  • fix(populate): allow deselecting discriminator key when populating #​14155 #​3230
  • fix: allow adding discriminators using Schema.prototype.discriminator() to subdocuments after defining parent schema #​14131 #​14109
  • fix(schema): avoid creating unnecessary clone of schematype in nested array so nested document arrays use correct constructor #​14128 #​14101
  • fix(populate): call transform object with single id instead of array when populating a justOne path under an array #​14135 #​14073
  • types: add back mistakenly removed findByIdAndRemove() function signature #​14136 #​14132

v7.6.6

Compare Source

==================


Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate label Dec 3, 2024
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v8 [security] fix(deps): update dependency mongoose to v8 [security] - autoclosed Dec 4, 2024
@renovate renovate Bot closed this Dec 4, 2024
@renovate
renovate Bot deleted the renovate/npm-mongoose-vulnerability branch December 4, 2024 17:41
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v8 [security] - autoclosed fix(deps): update dependency mongoose to v8 [security] Dec 4, 2024
@renovate renovate Bot reopened this Dec 4, 2024
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 25d05b0 to 075ced8 Compare December 4, 2024 20:03
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v8 [security] fix(deps): update dependency mongoose to v7.8.3 [security] Dec 4, 2024
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 075ced8 to 6a3976e Compare December 4, 2024 23:14
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 6a3976e to 4fe2b2f Compare January 17, 2025 04:11
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v7.8.3 [security] fix(deps): update dependency mongoose to v8 [security] Jan 17, 2025
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 4fe2b2f to 3040b1b Compare January 19, 2025 08:21
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v8 [security] fix(deps): update dependency mongoose to v7.8.4 [security] Jan 19, 2025
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 3040b1b to b6301af Compare August 10, 2025 13:58
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from b6301af to c214024 Compare December 31, 2025 15:17
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch 2 times, most recently from 1b66a14 to babc661 Compare January 23, 2026 19:42
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from babc661 to 79b52b3 Compare February 2, 2026 16:32
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 79b52b3 to d66701f Compare February 12, 2026 12:08
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v7.8.4 [security] fix(deps): update dependency mongoose to v7.8.4 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v7.8.4 [security] - autoclosed fix(deps): update dependency mongoose to v7.8.4 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch 3 times, most recently from a53f1f1 to 28518ad Compare April 1, 2026 20:34
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 28518ad to b1799f0 Compare April 8, 2026 18:34
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v7.8.4 [security] fix(deps): update dependency mongoose to v7.8.4 [security] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v7.8.4 [security] - autoclosed fix(deps): update dependency mongoose to v7.8.4 [security] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch 3 times, most recently from 742a81e to 0a9bb71 Compare April 29, 2026 20:12
@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 0a9bb71 to 6411604 Compare May 12, 2026 10:34
@renovate

renovate Bot commented May 12, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
[WARN] The "pnpm" field in package.json is no longer read by pnpm. The following keys were ignored: "pnpm.overrides". See https://pnpm.io/settings for the new home of each setting.
Error: ERR_PNPM_NO_MATCHING_VERSION

  × installing dependencies
  ╰─▶ Failed to resolve dependency tree: No matching version found for
      has@1.0.29 while fetching it from https://registry.npmjs.org/
  help: The latest release of has is "1.0.4".
        
        If you need the full list of all 6 published versions run "pnpm view
        has versions".


@renovate
renovate Bot force-pushed the renovate/npm-mongoose-vulnerability branch from 6411604 to b2b9aa4 Compare August 26, 2026 15:07
@renovate renovate Bot changed the title fix(deps): update dependency mongoose to v7.8.4 [security] fix(deps): update dependency mongoose to v7.8.10 [security] Aug 26, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants