mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the toBSON method. A misuse of the vm dependency to perform exec commands in a non-safe environment.
toBSON
vm
exec
{ "versions": [ { "introduced": "0" }, { "fixed": "0.54.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10758.json"