CVE-2019-10758
mongo-express
Published 24 Dec 2019 · updated 17 Jun 2026 · Analyzed
9.9 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Dec 2021, with a remediation deadline of 10 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
References
- snyk.io/vuln/SNYK-JS-MONGOEXPRESS-473215 · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-10758 · US Government Resource