CVE-2019-10758: MongoDB mongo-express Remote Code Execution Vulnerability
Critical severity, CVSS 9.9. Actively exploited: in CISA KEV since 2021-12-10. EPSS: 84.7% chance of exploitation in the next 30 days.
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
Affected products
- Mongo-Express Project mongo-express: before 0.54.0 (fixed in 0.54.0)
Published 2019-12-24. Last modified 2026-06-17.