- Description
- mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0
- Source
- cna@mongodb.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 6
- Exploitability score
- 0.8
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- cna@mongodb.com
- CWE-426
- Hype score
- Not currently trending
New post from https://t.co/uXvPWJy6tj (CVE-2025-1756 | MongoDB mongosh up to 2.2.x File C:node_modules untrusted search path (RHSA-2025:1756)) has been published on https://t.co/tU7RWXqtGm
@WolfgangSesin
28 Feb 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MongoDB Compass and Shell may be susceptible to local privilege escalation inWindowsURL: https://t.co/8EGK6uf0NJ: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5CVEs: CVE-2025-1755, CVE-2025-1756See also: https://t.co/4LTNldNJfc
@CharyyevPerman
28 Feb 2025
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1756 Local Privilege Escalation in mongosh Prior to 2.3.0 via Node Modules Directory https://t.co/5cCNyGdgNa
@VulmonFeeds
27 Feb 2025
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ MongoDB Security Advisory: February 2025 Vulnerabilities *1. Local Privilege Escalation Vulnerabilities* *CVE-2025-1756 (MongoDB Shell)* 📅 Timeline: Disclosure: 2025-02-27 & Patch Release: 2025-02-27 🆔 CVE ID: CVE-2025-1756 📊 CVSS v3.1: Score: 7.5 (High 🟠) Vector:… h
@syedaquib77
27 Feb 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes