CVE-2019-10758

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/12/2019
Last modified:
27/10/2025

Description

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mongo-express_project:mongo-express:*:*:*:*:*:node.js:*:* 0.54.0 (excluding)