CVE-2023-3696: Mongoosejs Mongoose

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.

Affected products

  • Mongoosejs Mongoose: before 5.13.20 (fixed in 5.13.20); from 6.0.0, before 6.11.3 (fixed in 6.11.3); from 7.0.0, before 7.3.4 (fixed in 7.3.4)

Published 2023-07-17. Last modified 2026-06-17.