Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/mongodb-js/compass/releases/tag/v1.49.12 |
|
Thu, 24 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database. | |
| Title | Shell script injection via server-supplied database name in Open MongoDB shell | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-24T17:09:54.602Z
Reserved: 2026-09-23T15:45:51.994Z
Link: CVE-2026-96750
Updated: 2026-09-24T17:09:46.312Z
Status : Received
Published: 2026-09-24T16:17:27.610
Modified: 2026-09-24T18:19:08.930
Link: CVE-2026-96750
No data.
OpenCVE Enrichment
No data.