Description
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass’ connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2.
Recommendation
Update the @mongodb-js/connection-form package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.20.1
- Patched version(s): 1.20.1
References
Related Issues
- s3-url-parser vulnerable to Denial of Service via regexes component - CVE-2024-25355
- KaTeX's maxExpand bypassed by Unicode sub/superscripts - CVE-2024-28244
- json-schema-ref-parser Prototype Pollution issue - CVE-2024-29651
- Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser - CVE-2026-33349
You might also like:
- Tags:
- npm
- @mongodb-js/connection-form
Anything's wrong? Let us know Last updated on February 27, 2025


