First published: Thu Feb 27 2025(Updated: )
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
Credit: cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB Compass | <1.42.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1755 is classified as a local privilege escalation vulnerability in MongoDB Compass.
To fix CVE-2025-1755, upgrade MongoDB Compass to version 1.42.1 or later.
MongoDB Compass versions prior to 1.42.1 are affected by CVE-2025-1755.
CVE-2025-1755 may allow unauthorized actions on a user's system with elevated privileges.
No specific workaround is provided for CVE-2025-1755; the best mitigation is to upgrade to the fixed version.