BIT-mongodb-2025-6713

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mongodb/BIT-mongodb-2025-6713.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mongodb-2025-6713
Aliases
Published
2025-10-05T23:44:16.574Z
Modified
2025-10-06T07:14:32.318632Z
Summary
MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage
Details

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*"
    ]
}
References

Affected packages

Bitnami / mongodb

Package

Name
mongodb
Purl
pkg:bitnami/mongodb

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0
Fixed
6.0.22
Introduced
7.0.0
Fixed
7.0.19
Introduced
8.0.0
Fixed
8.0.7

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/mongodb/BIT-mongodb-2025-6713.json"