@mongosh/shell-api@0.0.1-alpha.14 vulnerabilities

MongoDB Shell API Classes Package

  • latest version

    3.5.0

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @mongosh/shell-api package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    @mongosh/shell-api is a MongoDB Shell API Classes Package

    Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the autocomplete feature. An attacker with control over the mongosh autocomplete feature can manipulate the autocompletion to input and execute obfuscated malicious text by tricking a user into using the 'tab' key to complete a command.

    Note:

    This is only exploitable when mongosh is connected to a cluster that is partially or fully controlled by the attacker.

    How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')?

    Upgrade @mongosh/shell-api to version 3.0.0 or higher.

    <3.0.0