CVE-2025-1691

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Feb 27, 2025
CWE ID 74

Summary

CVE-2025-1691 introduces a control character injection vulnerability in the MongoDB Shell. An attacker who gains control of the mongosh autocomplete feature can input and run obfuscated malicious text by leveraging user interaction through the 'tab' key for text completion. This issue only affects mongosh versions prior to 2.3.9 and is exploitable when mongosh is connected to a cluster controlled by the attacker.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share