CVE-2024-53900: Mongoosejs Mongoose

Critical severity, CVSS 9.1. EPSS: 4% chance of exploitation in the next 30 days.

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

Affected products

  • Mongoosejs Mongoose: before 6.13.5 (fixed in 6.13.5); from 7.0.1, before 7.8.3 (fixed in 7.8.3); from 8.0.1, before 8.8.3 (fixed in 8.8.3); version 7.0.0 only; version 8.0.0 only

Published 2024-12-02. Last modified 2026-06-17.