CVE-2026-9101: MongoDB Compass
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.
Affected products
- MongoDB Compass: version 1.36.3 only; version 1.36.4 only; version 1.37.0 only; version 1.38.0 only; version 1.38.1 only; version 1.38.2 only; …
Published 2026-05-20. Last modified 2026-09-24.