Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
{ "severity": "Critical", "cpes": [ "cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:*" ] }
"https://github.com/bitnami/vulndb/tree/main/data/mongoose/BIT-mongoose-2024-53900.json"