An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22
{
"cwe_ids": [
"CWE-285"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6713.json",
"cna_assigner": "mongodb",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "6.0"
},
{
"fixed": "6.0.22"
},
{
"introduced": "7.0"
},
{
"fixed": "7.0.19"
},
{
"introduced": "8.0"
},
{
"fixed": "8.0.7"
}
]
}
]
}{
"cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.22"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.19"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.7"
}
]
}"2026-07-22T04:02:49Z"
[
{
"signature_type": "Line",
"target": {
"file": "src/mongo/db/pipeline/lite_parsed_document_source.h"
},
"deprecated": false,
"source": "https://github.com/mongodb/mongo/commit/6cf88233f0c649695862b1b5be20c04b87f7e8f1",
"id": "CVE-2025-6713-0b4e0751",
"signature_version": "v1",
"digest": {
"line_hashes": [
"214643683530774032100036489942452737529",
"318477943940252881987496373792852256683",
"198474435809438694509794776280487724710"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/s/query/document_source_merge_cursors.cpp"
},
"deprecated": false,
"source": "https://github.com/mongodb/mongo/commit/6cf88233f0c649695862b1b5be20c04b87f7e8f1",
"id": "CVE-2025-6713-2653d96c",
"signature_version": "v1",
"digest": {
"line_hashes": [
"138467260949863329498805639538379507808",
"223198180086728900778837498337912589521",
"148430034972700418827909772528237080451",
"98898776309116250111447806208156160681",
"140132014256917882686791854219027715215",
"2073529888411466178012965154365761325",
"23439098951180303377135904545527049056"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/s/query/document_source_merge_cursors.cpp"
},
"deprecated": false,
"source": "https://github.com/mongodb/mongo/commit/f2b89463945f47376156f270dbf193f74484a623",
"id": "CVE-2025-6713-5690edc3",
"signature_version": "v1",
"digest": {
"line_hashes": [
"167971444258294881142130961071240963937",
"40580703834568146500067455680138133324",
"148430034972700418827909772528237080451",
"98898776309116250111447806208156160681",
"140132014256917882686791854219027715215",
"2073529888411466178012965154365761325",
"23439098951180303377135904545527049056"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/s/query/document_source_merge_cursors.cpp"
},
"deprecated": false,
"source": "https://github.com/mongodb/mongo/commit/fc15786481d4e5e9ae1192425944e19d446a418e",
"id": "CVE-2025-6713-59c2835d",
"signature_version": "v1",
"digest": {
"line_hashes": [
"138467260949863329498805639538379507808",
"223198180086728900778837498337912589521",
"148430034972700418827909772528237080451",
"98898776309116250111447806208156160681",
"140132014256917882686791854219027715215",
"2073529888411466178012965154365761325",
"23439098951180303377135904545527049056"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/db/pipeline/lite_parsed_document_source.h"
},
"deprecated": false,
"source": "https://github.com/mongodb/mongo/commit/f2b89463945f47376156f270dbf193f74484a623",
"id": "CVE-2025-6713-ddf202f8",
"signature_version": "v1",
"digest": {
"line_hashes": [
"214643683530774032100036489942452737529",
"318477943940252881987496373792852256683",
"198474435809438694509794776280487724710"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/db/pipeline/lite_parsed_document_source.h"
},
"deprecated": false,
"source": "https://github.com/mongodb/mongo/commit/fc15786481d4e5e9ae1192425944e19d446a418e",
"id": "CVE-2025-6713-fb98bdd7",
"signature_version": "v1",
"digest": {
"line_hashes": [
"214643683530774032100036489942452737529",
"318477943940252881987496373792852256683",
"198474435809438694509794776280487724710"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6713.json"