CVE-2025-1755

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 27, 2025
CWE ID 426

Summary

CVE-2025-1755 is a local privilege escalation vulnerability affecting MongoDB Compass. Under specific conditions, an attacker can store a crafted file in the C:\\node_modules\\ directory, potentially enabling unauthorized actions on a user's system with elevated privileges. This issue affects MongoDB Compass versions prior to 1.42.1. Successful exploitation of this vulnerability could lead to significant security risks and system compromise. Users are strongly encouraged to update their MongoDB Compass software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MongoDB Compass

Affected Vendors

  • MongoDB Inc