chore(deps): update dependency mongoose to v6 [security]#346
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency mongoose to v6 [security]#346renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
June 4, 2023 12:03
a3b8c3b to
ec9c54a
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
3 times, most recently
from
June 19, 2023 08:23
5a62d03 to
65d34b9
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
June 29, 2023 11:02
65d34b9 to
c7f81ee
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
July 9, 2023 10:44
5232bd3 to
d66ff08
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
July 19, 2023 10:57
90050bf to
f68ffca
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
July 27, 2023 18:38
f68ffca to
bf8a510
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
September 19, 2023 13:20
bf8a510 to
9775392
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
October 9, 2023 10:27
9775392 to
c94c803
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
October 23, 2023 13:09
c94c803 to
1e42e85
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
November 6, 2023 07:20
1e42e85 to
64ac3c7
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
February 4, 2024 11:11
4ffcd6e to
a9c5d90
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
February 25, 2024 10:13
a9c5d90 to
1138695
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
April 14, 2024 08:48
1138695 to
147d659
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
April 25, 2024 07:32
147d659 to
467d247
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
June 4, 2024 11:40
467d247 to
3594718
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
July 21, 2024 14:36
3594718 to
1db2bce
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
August 6, 2024 09:32
1db2bce to
8fcda80
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
August 28, 2024 08:32
8fcda80 to
99fc925
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
October 9, 2024 07:50
99fc925 to
df22abf
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
December 3, 2024 04:23
56c878b to
fd59444
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
December 4, 2024 18:40
fd59444 to
516bbd3
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
March 17, 2025 12:47
02c78fd to
2d1f936
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
April 8, 2025 13:29
751c5f6 to
0b06613
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
April 24, 2025 07:18
0b06613 to
4349747
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
May 19, 2025 21:21
4349747 to
50dc413
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
June 4, 2025 06:00
c6d5009 to
4789720
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
June 22, 2025 13:33
4789720 to
e37ecf5
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
July 2, 2025 18:16
e37ecf5 to
1fdb555
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
2 times, most recently
from
August 13, 2025 14:36
21fd330 to
490235c
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
August 31, 2025 10:44
490235c to
de62cd6
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
September 25, 2025 16:46
de62cd6 to
70f5f83
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
October 21, 2025 09:10
70f5f83 to
19af368
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
November 11, 2025 00:33
19af368 to
edc1ee1
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
November 18, 2025 09:59
edc1ee1 to
9c38f35
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
December 3, 2025 18:10
9c38f35 to
d323bc9
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
December 31, 2025 15:35
d323bc9 to
0a8c0bc
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
January 8, 2026 17:17
0a8c0bc to
fcf43cb
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
January 19, 2026 17:35
fcf43cb to
d98b4d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
3 times, most recently
from
February 5, 2026 00:44
10c9860 to
3ca442e
Compare
renovate
Bot
force-pushed
the
renovate/npm-mongoose-vulnerability
branch
from
March 5, 2026 15:52
3ca442e to
ec4e7b6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.8.5→6.13.6automattic/mongoose vulnerable to Prototype pollution via Schema.path
CVE-2022-2564 / GHSA-f825-f98c-gj3g
More information
Details
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The
Schema.path()function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Mongoose Prototype Pollution vulnerability
CVE-2023-3696 / GHSA-9m93-w8w6-76hh
More information
Details
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.
Severity
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Mongoose Vulnerable to Prototype Pollution in Schema Object
CVE-2022-24304 / GHSA-h8hf-x3f4-xwgp
More information
Details
Description
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.
Affected versions of this package are vulnerable to Prototype Pollution. The
Schema.path()function is vulnerable to prototype pollution when setting theschemaobject. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.Proof of Concept
Impact
This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Mongoose search injection vulnerability
CVE-2025-23061 / GHSA-vg7j-7cwx-8wgw
More information
Details
Mongoose versions prior to 8.9.5, 7.8.4, and 6.13.6 are vulnerable to improper use of the
$whereoperator. This vulnerability arises from the ability of the$whereclause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Mongoose search injection vulnerability
CVE-2024-53900 / GHSA-m7xq-9374-9rvx
More information
Details
Mongoose versions prior to 8.8.3, 7.8.3, 6.13.5, and 5.13.23 are vulnerable to improper use of the $where operator. This vulnerability arises from the ability of the $where clause to execute arbitrary JavaScript code in MongoDB queries, potentially leading to code injection attacks and unauthorized access or manipulation of database data.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
Automattic/mongoose (mongoose)
v6.13.6Compare Source
===================
v6.13.5Compare Source
===================
v6.13.4Compare Source
===================
v6.13.3Compare Source
===================
v6.13.2Compare Source
===================
v6.13.1Compare Source
===================
v6.13.0Compare Source
===================
v6.12.9Compare Source
===================
v6.12.8Compare Source
===================
valueproperty rather than boolean #14418v6.12.7Compare Source
===================
openUri()#14370 #13376 #13335v6.12.6Compare Source
===================
v6.12.5Compare Source
===================
v6.12.4Compare Source
===================
v6.12.3Compare Source
===================
removeVirtual()#14019 #13085v6.12.2Compare Source
===================
v6.12.1Compare Source
===================
v6.12.0Compare Source
===================
v6.11.6Compare Source
===================
v6.11.5Compare Source
===================
v6.11.4Compare Source
===================
v6.11.3Compare Source
===================
v6.11.2Compare Source
===================
v6.11.1Compare Source
===================
v6.11.0Compare Source
===================
v6.10.5Compare Source
===================
v6.10.4Compare Source
===================
v6.10.3Compare Source
===================
v6.10.2Compare Source
===================
enginesinpackage.json#13124 lorand-horvathv6.10.1Compare Source
===================
$andand$or#13086 #12898Model.populate()#13070v6.10.0Compare Source
===================
v6.9.3Compare Source
==================
autoCreateandautoIndexuntil after initial connection established #13007 #12940 lpizzinidevv6.9.2Compare Source
==================
v6.9.1Compare Source
==================
v6.9.0Compare Source
==================
$orconditions after strict applied #12898 0x0a0dv6.8.4Compare Source
==================
v6.8.3Compare Source
==================
v6.8.2Compare Source
==================
v6.8.1Compare Source
==================
$localsparameters to getters/setters tutorial #12814 #12550 IslandRhythmsv6.8.0Compare Source
==================
localFieldandforeignFieldfor virtual populate #12657 #6963 IslandRhythmsv6.7.5Compare Source
==================
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.