CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-10758

Known Exploited (CISA KEV)CRITICAL
9.9
CVSS Severity Score
EPSS Score80.9650%
EPSS Percentile95.35th
Published2019年12月24日
Last Modified2025年10月27日

Vulnerability Description

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

Affected Platforms (CPE)

📦
Mongo Express Project

Mongo Express

< 0.54.0

References & Advisories

相关漏洞威胁