MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://jira.mongodb.org/browse/COMPASS-9058 | vendor advisory issue tracking |
https://access.redhat.com/errata/RHSA-2025:1755.html | third party advisory |