Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53900.json"