mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://jira.mongodb.org/browse/MONGOSH-2028 | vendor advisory issue tracking |
https://access.redhat.com/errata/RHSA-2025:1756 | third party advisory |