CVE-2025-1691
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Feb 27, 2025
CWE ID 74
Summary
CVE-2025-1691 introduces a control character injection vulnerability in the MongoDB Shell. An attacker who gains control of the mongosh autocomplete feature can input and run obfuscated malicious text by leveraging user interaction through the 'tab' key for text completion. This issue only affects mongosh versions prior to 2.3.9 and is exploitable when mongosh is connected to a cluster controlled by the attacker.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- MongoDB Inc