CVE-2025-23061: Mongoosejs Mongoose

Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.

Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

Affected products

  • Mongoosejs Mongoose: before 6.13.6 (fixed in 6.13.6); from 7.0.0, before 7.8.4 (fixed in 7.8.4); from 8.0.0, before 8.9.5 (fixed in 8.9.5)

Published 2025-01-15. Last modified 2026-06-17.