ZeroHour

CVE-2025-1756

CVSS 3.1
7.8 high
EPSS
<1%p4
Published
()
Modified
Description

mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0

Vendors
mongodbredhat
Products
mongosh, codeready linux builder eus, codeready linux builder for arm64 eus, codeready linux builder for ibm z systems eus, codeready linux builder for power little endian eus, enterprise linux update services for sap solutions, enterprise linux eus, enterprise linux for arm 64, enterprise linux for arm 64 eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power little endian eus
Weakness
CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.