Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/mongodb-js/compass/releases/tag/v1.49.12 |
|
Thu, 24 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb compass |
|
| Vendors & Products |
Mongodb
Mongodb compass |
Thu, 24 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database. | |
| Title | Shell script injection via server-supplied database name in Open MongoDB shell | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-24T17:09:54.602Z
Reserved: 2026-09-23T15:45:51.994Z
Link: CVE-2026-96750
Updated: 2026-09-24T17:09:46.312Z
Status : Awaiting Analysis
Published: 2026-09-24T16:17:27.610
Modified: 2026-09-24T21:00:46.893
Link: CVE-2026-96750
No data.
OpenCVE Enrichment
Updated: 2026-09-24T21:30:17Z
